SSL VPN Logging & Brute Force Attacks
Hey everyone, I have a customer who is constantly being attacked on our SSL VPN interface. I enabled block policies after 3 failed attempts and they get blocked for 6 months. It worked well for a little while but now they are using spoofing to change their IP every attempt. So rendering my blocking useless. I wouldn't care so much but I am constantly getting failed login attempt alerts emails now. Super annoying. I've gotten 5 since I've started writing this. Anyway, anyone see any way that I could stop this from happening? I would like to keep the logging on as its useful for me but I am thinking about just turning it off completely as this point.
