cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who rated this post

L4 Transporter

The best way to block GlobalProtect brute-force attempts at the firewall is to use a Vulnerability Protection Profile.

  1. Create a Vulnerability Protection Profile: Go to Objects > Security Profiles > Vulnerability Protection.

  2. Add a block-ip exception: Edit the profile and add an exception for signature ID 40017 ("Palo Alto Networks GlobalProtect Authentication Brute Force Attempt").

  3. Configure the block: Set the action to block-ip and define the number of failed attempts, the time window, and the block duration (e.g., 604800 seconds for a week).

  4. Apply the profile: Apply this new profile to the security policy that allows traffic to your GlobalProtect portal.

This will automatically and silently drop connections from a source IP after a set number of failed attempts, preventing them from ever reaching your identity provider.

Best Regards,
Suresh
Who rated this post