US VPN Brute Force
I've followed some of the most posted protocols for preventing brute force on my vpn interface, biggest was to only allow US based traffic to the interface, but what I've found in the last coupld of years, is that all the open VPN environments in the US are used by threat actors constantly. I'm up to about 3000 failed login attempts in 6 hours time. This is just US based IP's and when I look them up, the bulk of them are associated to open VPN providers IN the US.
I was doing some searching to see if there are geo lists of these open vpn providers that I could import. I've been manually digging up the blocks and doing ASN/Whois lookups to piece it together. I get it down to about 200 / 6 hours, but then in a couple of weeks, shoots back up to the 1K's of hits. Anyone have suggestions? Again, this is US only attacks at this point.

