In my company we are using GlobalProtect VPN's as a medium to access the network.
Right now we have a blocking procedure by which if a user fails 5 times the password while trying to login, his account gets blocked for 15 minutes.
We are using this -> https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClJ2CAK
Recently we have had an audit and they found out we were not protected against a Password Spraying attack so we would like to block users based on accumulation too.
- If a user fails 5 times, block 15 minutes
- If a user fails 5 times more, block 1h
- If a user fails 5 times more, block 24h
I have not found anyone talking about this in the forum and I would like to know if there is any way to get this done within GlobalProtect.
Thank you very much!
While PAN does not offer this and neither does active directory, to my knowledge. You can protect yourself in other ways. Check out this article.
Do you have a DoS policy on this service at all? My line of thinking would be that usually a Password Spraying attack would be launched in rapid succession, which would cause a larger amount of sessions to be opened. You could use the DoS Session Limit to kind of prevent this and lock out the IP that the attack is being launched from.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!