Global Protect

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Global Protect

L3 Networker

Hi Friends,

 

We have a requirement related to global protect.

Condition:

User tries to connect to global protect and fails to login.

If he tries for three or more times to connect to global protect and fails to login an email alert should come to my mail id.

 

I have configured email alerts in my firewall but can we specifically customize by above mentioned condition. 

Could you please help me with the requirement is it possible or not ?

 

Regards

Satya Kalyan.

2 REPLIES 2

Cyber Elite
Cyber Elite

Device >Authentication Profile > Auth-profile-name > Advanced Tab

Set "Failed Attempts" and "Lockout Time"

 

 

Raido_Rattameister_0-1685295892666.png

 

After 3 failed login attempts account will be locked.

Those attempts will generate event in "Monitor > System" but not if account locks up.

 

When user tries 4th time then "Monitor > System" will log event that can be tracked using following filter.

( description contains 'User is in locked users list' )

 

So if you set up email notification under "Device > Log Setting > System" using this filter you will get alert if locked in users try to log in.

 

Raido_Rattameister_1-1685296320439.png

 

 

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Hi Raido,

 

Thankyou for the information.

 

Regards

Satya Kalyan.

  • 1079 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!