Multiple bogus credentials on GP portal

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Multiple bogus credentials on GP portal

L3 Networker

I have noticed there are alot of random IPs that are trying to login to my GP portal. We are using pre-login method of GP so legit users do not login. GP starts and does an auto-login pre-windows login. The logs tell me these failures are coming from GP portal. They are not getting anywhere since a trusted cert on legit users PCs is required, but is there anyway to stop this from happening? Anyway to prevent users from trying to access my GP portal or gateway?

2 REPLIES 2

Cyber Elite
Cyber Elite

Hi @S_Williams901 ,

 

You could ...

 

  1. Disable the Portal Login Page under the General tab.  That will stop the vast majority.
  2. Deny all countries to your GP portal and gateway except the ones you want.
  3. Deny all protocols to your GP portal and gateway except panos-global-protect and ipsec-esp-udp.
  4. Deny PANW and 3rd party EDLs inbound.

Obviously you would need to enable the portal login page and ssl if you want to download the client.  (Technically, the portal login page is not required if you go to yourdoamin.com/global-protect/getsoftwarepage.esp, but that is another story.)

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

Nothing stops a user from downloading a gp client somewhere on the internet and trying to hit my gateway with bogus usernames correct?

  • 585 Views
  • 2 replies
  • 0 Likes
  • 47 Subscriptions
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!