prevent-brute-force-attacks

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

prevent-brute-force-attacks

L0 Member

Hello Everyone

 

I am looking for suggestions on how we could protect our GlobalProtect VPN. We have been seeing people trying to perform brute-force attacks on random user accounts daily. We do have MFA set up, but is there any automation we could implement with Palo Alto Firewall to automatically block IP addresses after a certain number of failed attempts?"


3 REPLIES 3

Cyber Elite
Cyber Elite

Hi @dshastri ,

 

Here is a great place to start.  https://www.packetswitch.co.uk/how-to-protect-globalprotect-portal-from-brute-force-attack/

 

I have used all of these methods.  They will significantly decrease the amount you are getting.

 

The 4th one is a vulnerability signature that does mostly what you ask.  I found it to not be as effective since most of my hackers were low and slow.  The signature only detects login attempts and not failures.  So, you can't tune it too tight or valid users may be blocked.

 

GP can still be used without the portal page enabled.  (You actually can still download software by going to https://your.domain.com/global-protect/getsoftwarepage.esp, but that's another story.)

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

Cyber Elite
Cyber Elite

Hello,

In addition to this, I recommend implmenting Zone Protection profiles.

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clm9CAC

Regards,

Thank You TomYoung the only thing I am missing from the documentation was Blacklist IPs Using a Vulnerability Profile. Do you know if Palo Alto has a pre authentication check where if the user doesn't exist on the group, it drops the connection? 

  • 352 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!