- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-03-2025 10:20 AM
The best way to block GlobalProtect brute-force attempts at the firewall is to use a Vulnerability Protection Profile.
Create a Vulnerability Protection Profile: Go to Objects > Security Profiles > Vulnerability Protection.
Add a block-ip
exception: Edit the profile and add an exception for signature ID 40017 ("Palo Alto Networks GlobalProtect Authentication Brute Force Attempt").
Configure the block: Set the action to block-ip
and define the number of failed attempts, the time window, and the block duration (e.g., 604800 seconds for a week).
Apply the profile: Apply this new profile to the security policy that allows traffic to your GlobalProtect portal.
This will automatically and silently drop connections from a source IP after a set number of failed attempts, preventing them from ever reaching your identity provider.