Skip to main content
SecurityPlus
Explorer III
June 8, 2024
Question

Improve SSL VPN Security / Reduce SSL Login Fail Messages

  • June 8, 2024
  • 7 replies
  • 16966 views

I have read many helpful posts concerning SSL VPN security and different approaches that can be used to improve security. So far we have unique usernames, strong unique passwords, and geo filtering from the SSL-VPN Settings / Restrict access to specific hosts field, security measures in place. Most firewalls are running FortiOS 7.2.7 or 6.2.16.

 

We see a lot of messages that say:

The following critical firewall event was detected: SSL VPN login fail.

 

I would like to improve security and would like to have a much shorter list of SSL VPN login fail messages to review. The shorter list would help us to verify if attempts are being made using actual SSL VPN users on the firewall (more likely to be able to log in) or of a bad actor is simply guessing random usernames (unlikely to be successful in logging in).

 

Does using geo filtering in a local in policy work the same way that it works on the SSL-VPN Settings / Restrict access to specific hosts field? In other words, do both, when violated, still trigger an SSL VPN login fail event message?

 

If two-factor authentication were used via User Definition, would an attempted login that is within the allowed geo area(s), and fails due to an incorrect password, or failure of the user to enter the correct two-factor authentication, still also trigger the SSL VPN login fail event message?

 

I would be interested to know too what in your opinion is the next best security improvement that we should consider? My hesitation in utilizing two-factor authentication has been the time to setup, the impact on the end user, and the cost.

7 replies

DPadula
Staff & Editor
Staff & Editor
June 9, 2024

Hi @SecurityPlus

Before answering you question, let me ask you something. Any reason why not use IPSec instead of SSL-VPN for the users with FortiClient?

SecurityPlus
Explorer III
June 9, 2024

The only reason might be lack of experience with it. I have used it from FortiGate to FortiGate with good success. Have hardly used it for a user to connect from a PC to the firewall. Is this recommend in lieu of SSL VPN?

rvillaroman
Staff & Editor
Staff & Editor
June 10, 2024

 

Hi @SecurityPlus ,

 

The following critical firewall event was detected: SSL VPN login fail.

 

You may get this error when a user is trying to connect to the device using the wrong password or non-existing username on your SSLVPN group mapping and authentication.

 

As SSLVPN is publicly available, some malicious users are trying to brute-force your connection by using a generic username and password. That is why strong password encryption is a must.

 

To narrow down the list of geo-locations that can access your connection, on the SSL-VPN Settings, you could set only the allowed country on 'Limit access to specific hosts'. 

 

On the allowed geo-location, if you are still seeing some unathorized attempt, you could restrict the access using local-in policy and block their IP or subnet.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Restrict-unauthorized-access-on-the-SSL-VPN/ta-p/220413

 

As it may be too tedious to list the subnet one-by-one, you could make an automation stitch to block the IP of the user that failed to login to the VPN. 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Block-SSL-VPN-failed-logins-with-an-automation/ta-p/287171

Note: 

This will block legitimate users as well if the login attempt fails. It will be necessary to manually remove each user's public IP from this address object to allow them to connect to the VPN again.

 

Furthermore, as you are getting the notification "SSL VPN login fail", it means that the Fortigate is denying this unwanted connection and it is the expected behaviour. Using two-factor authentication is recommended as it provides another layer of protection.

SecurityPlus
Explorer III
June 10, 2024

Thanks rvillaroman. If 'Limit access to specific hosts' and/or use a local-in policy, will connection attempts that violate these criteria show up in the VPN login fail logs or will these be denied before the log records the failure.

rvillaroman
Staff & Editor
Staff & Editor
June 11, 2024

If the IP or geo-location of the malicious users is not part of the allowed country or IP on  'Limit access to specific hosts', it will not log as "VPN login fail logs," but their access will be denied. This is the same on the local-in-policy. 

Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!