Brute Force GlobalProtect Portal via GP app

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Brute Force GlobalProtect Portal via GP app

L1 Bithead

I'm looking for a way to define a custom signature that can detect brute force attempts on the GlobalProtect portal that aren't based on the portal login page. I already have ID 40017 - VPN: Palo Alto Networks SSL VPN Authentication Brute Force Attempt - in place and working fine, however I realized that I'm seeing attacks now where someone has managed to replicate the auth sequence from the GP app itself. I've attempted using the following, but am not having any luck with it detecting my failed attempts:





Wireshark shows a 512 HTTP status code is returned when the auth fails:


I'm sure I'm missing something, so please let me know if you spot it or have dealt with this before.



L6 Presenter

If 512 is returned by the Palo Alto firewall maybe this is an issue why the signature does not work as the response is comming from the control plane.


You can try selecting transaction not session or as another workaround you can try placing the globalprotect gateway on the loopback interface / as maybe then firewall will match the signature when passing through the reply from the dataplane interface.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!