- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-27-2023 08:29 AM
Hello,
I would like to set failed attempts and lockout time on my Global Protect auth profile but I do not see where I can set this. The only place I see these settings is in the global profile but I would like to set this only for Global Protect. I am using v 10.2.4-h2
Thanks for any thoughts.
MJF
09-28-2023 09:28 AM - edited 09-28-2023 09:30 AM
SAML Profile for example don't have this option. You need to configure lockout on SAML/2FA provider side.
09-28-2023 06:58 AM
Lockoud time can be configured at
Device > Authentication Profile > Auth-Profile-Name > Advanced tab
You can also adjust vulnerability signature 40017 (Objects > Security Profiles > Vulnerability protection) if source IP should be blocked after specific number of failed login attempts.
09-28-2023 09:16 AM
Hello,
If your GP uses something like active directory, you could use a GPO to set something like, lockout after <> failed attempts and unlock after <>minutes.
Regards,
09-28-2023 09:26 AM
Thanks Raido
I will try the vulnerability Profile. When I go to the Auth profile and advanced, I am only seeing the allow list.
MJF
09-28-2023 09:28 AM - edited 09-28-2023 09:30 AM
SAML Profile for example don't have this option. You need to configure lockout on SAML/2FA provider side.
10-03-2023 12:39 PM
Can you provide details on how to do that? I've seen ID 40017 mentioned in older documentation but can't find anything that references how to do it. I'm trying to block IPs after a certain number of failed GP portal login attempts - I've got numerous brute force attempts happening.
10-03-2023 02:11 PM
If you go to Objects security profiles you can create a vulnerability profile there. If you add a vulnerability profile you can go to Exceptions and check all signatures then search for 40017 to edit. I was able to stop the brute force attacks by disabling the VPN web portal page because all my VPN users are using the client.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!