The intruder tries to connect via VPN
Hello,
I've an active VPN site-to-site tunnel between the headquarters and the branch office. I noticed in the logs, that since one week every day (more or less at the same time) someone makes one attempt to connect to the VPN on FGT at HQ and a moment later to the branch FGT.
Every time from similar IP addresses eg.:216.218.206.94 216.218.206.66 216.218.206.122 216.218.206.82 216.218.206.118 216.218.206.78 216.218.206.74 216.218.206.114 216.218.206.110 216.218.206.126 216.218.206.86 216.218.206.98 184.105.139.79 184.105.139.71 I would like to ask you, is there any way to block specified IP address or group of addresses (blacklist) to prevent the connection with my devices? (The Control Panel isn't available from the Internet). And the key question: how the intruder knew that I started a VPN site-to-site connection? How found out our HQ and Branch IP address?
log eg:
date=2016-09-28 time=03:10:59 devname=FGT60D-XX-HQ devid=FGT60DXX logid=0101037128 type=event subtype=vpn level=error vd="root" logdesc="Progress IPsec phase 1" msg="progress IPsec phase 1" action=negotiate remip=216.218.206.94 locip=193.XXX.XXX.XXX remport=31902 locport=500 outintf="wan1" cookies="3e35c70729dfedef/0000000000000000" user="N/A" group="N/A" xauthuser="N/A" xauthgroup="N/A" assignip=N/A vpntunnel="N/A" status=failure init=remote mode=main dir=inbound stage=1 role=responder result=ERROR
date=2016-09-28 time=03:40:43 devname=FGT60D-XX-BRANCH devid=FGT60DXX logid=0101037128 type=event subtype=vpn level=error vd="root" logdesc="Progress IPsec phase 1" msg="progress IPsec phase 1" action=negotiate remip=216.218.206.66 locip=157.XXX.XXX.XXX remport=52951 locport=500 outintf="wan1" cookies="3e35c70729dfedef/0000000000000000" user="N/A" group="N/A" xauthuser="N/A" xauthgroup="N/A" assignip=N/A vpntunnel="N/A" status=failure init=remote mode=main dir=inbound stage=1 role=responder result=ERROR
