Skip to main content
bmurphy7
Visitor III
December 12, 2024
Question

Block Ip address After X number of failed SSL-VPN Login attempts from said source IP addr.

  • December 12, 2024
  • 3 replies
  • 4754 views

Exactly as the title says. I have searched the forums and havent found anything that does this. Its either "use the admin lockout settings" or blocks after the first failed attempt, which will create and excess number of trouble tickets from end users if that is the case. I need the automation to check if the ip address has multiple failed attempts before adding the address to the block list. 

We do not have a fortianalyzer at this time. Is this possible without one or is a FortiAnalyzer required for this type of automation.

3 replies

funkylicious
SuperUser
SuperUser
December 12, 2024

config vpn ssl settings
set login-attempt-limit 3
set login-block-time 300

end

 

should do the trick

"jack of all trades, master of none"
bmurphy7
bmurphy7Author
Visitor III
December 12, 2024

Will this block the ip address. This is in response to brute force attempts coming from a vast random list of usernames. and as such needs blocked via Ip address permanently after X number of failed attempts from an ip address.

 

jjdope
Staff
Staff
December 12, 2024

Follow this article which tells how to use automation stitch for admin login. I believe there will be a trigger for ssl-vpn logon fail (article is for admin login fail)

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Block-FortiGate-Administrator-Login-with-an/ta-p/291355

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.