System Alert opaque: failed authentication for user ''. Reason: User is not in allowlist. auth profile 'GP', vsys 'vsys1', From: "public IP"

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

System Alert opaque: failed authentication for user ''. Reason: User is not in allowlist. auth profile 'GP', vsys 'vsys1', From: "public IP"

L2 Linker

Hi,

I've been receiving many system alerts with the message:

 

opaque: failed authentication for user ''. Reason: User is not in allowlist. auth profile '', vsys 'vsys1', From" "Public IP"

 

eventid: auth-fail

 

It looks like these public IP's are trying to access our internal network by coming through Global Protect App. Coming from many different random user names and public IP addresses. It seems that the Palo Alto firewall sends the credentials to the Active Directly Server and tharts when it fails.

Is there a way to prevent all these attempts without even having it go to the AD server?

 

Thanks.

1 REPLY 1

Hi @roma ,

The error message you receive actually tell the opposite - "Reason: User is not in allowlist"

When you configure your Authentication Profile, there is a tab to specify list of users or user groups that are allowed to authenticate with that profile.

Firewall will first take the provide username and compare it with this allow list. If it doesn't match any of the allowed users/user groups, FW will deny user authentication, without even sending the credentials to AD for validation

aleksandarastardzhiev_0-1688719447341.png

https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/device/device-authentication-...

 

  • 2133 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!