Skip to main content
luca1994
Explorer III
August 8, 2024
Question

VPN SSL Autoban IP

  • August 8, 2024
  • 2 replies
  • 1379 views

Hello Team,

 

This is the scenario:

FGT firewall offering SSL VPN service
Is there any way to do these things?
1. Autoban IP same user wrong password 5 attempts over 10 minutes

2. Autoban IP different user wrong password 10 attempt over 30 minutes

 

Thanks for the support
BR

2 replies

ozkanaltas
Valued Contributor III
August 8, 2024

Hello @luca1994 ,

 

Actually Fortigate does this automatically. But it just looks IP address of who tried. If a person has tried to login with the same IP address after 2 tries FortiGate will ban the IP address of the client for 60 seconds.

 

If you want, you can change this setting with these cli commands.

 

config vpn ssl settings set login-attempt-limit 2 set login-block-time 60 end

 

If you want to take more specific action for a ban, you can use automation for that. It can follow the logs with automation and it can take action for you. 

arahman
Staff
Staff
August 8, 2024

Hi, you can configure the automation stitch and do the same. as mentioned in the article below 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Block-SSL-VPN-failed-logins-with-an-automation/ta-p/287171

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!