Question
Block Ip address After X number of failed SSL-VPN Login attempts from said source IP addr.
Exactly as the title says. I have searched the forums and havent found anything that does this. Its either "use the admin lockout settings" or blocks after the first failed attempt, which will create and excess number of trouble tickets from end users if that is the case. I need the automation to check if the ip address has multiple failed attempts before adding the address to the block list.
We do not have a fortianalyzer at this time. Is this possible without one or is a FortiAnalyzer required for this type of automation.
