Improve SSL VPN Security / Reduce SSL Login Fail Messages
I have read many helpful posts concerning SSL VPN security and different approaches that can be used to improve security. So far we have unique usernames, strong unique passwords, and geo filtering from the SSL-VPN Settings / Restrict access to specific hosts field, security measures in place. Most firewalls are running FortiOS 7.2.7 or 6.2.16.
We see a lot of messages that say:
The following critical firewall event was detected: SSL VPN login fail.
I would like to improve security and would like to have a much shorter list of SSL VPN login fail messages to review. The shorter list would help us to verify if attempts are being made using actual SSL VPN users on the firewall (more likely to be able to log in) or of a bad actor is simply guessing random usernames (unlikely to be successful in logging in).
Does using geo filtering in a local in policy work the same way that it works on the SSL-VPN Settings / Restrict access to specific hosts field? In other words, do both, when violated, still trigger an SSL VPN login fail event message?
If two-factor authentication were used via User Definition, would an attempted login that is within the allowed geo area(s), and fails due to an incorrect password, or failure of the user to enter the correct two-factor authentication, still also trigger the SSL VPN login fail event message?
I would be interested to know too what in your opinion is the next best security improvement that we should consider? My hesitation in utilizing two-factor authentication has been the time to setup, the impact on the end user, and the cost.
