SSLVPN bad logins are increasing and with office username
Hi!
We are using MFA for SSL VPN. I can see now that bad actors are using our internal users name to try login to SSL VPN. They use proxy addresses from US. UK, Germany etc so blocking of geographic location is not possible as its not coming from some problematic countries.
I have see couple of posts that people are using some external connectors to block IP addresses based on its reputation.
If someone can point me to a documentation of how to setup some external connector and which service is best to buy for IP reputation.
How many of you such solution and if there are cons to it?
Thanks
