Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Fortigate VPN ban IPs
Hello,
Is there a fail2ban-like feature in Fortigate? I'm running VPN server on my 60f and I want it to block all IPs with more than 3 failed login attempts
Thank you
Labels:
- Labels:
-
FortiGate
3 REPLIES 3
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can have your VPN terminated on a loopback and set up an IPS profile on the resulting FW policy that would be required.
Cheers,
Graham
Graham
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
you don't really need fail2ban as there is a built-in feature for this in Fortigate:
CLI:
config vpn ssl settings
set login-attempt-limit [0-10] Default is 2.
set login-block-time [0-86400] Default is 60 seconds.
end
You can ban the failed logins IP for a duration of up to 24 hours.
Yuri Slobodyanyuk
Yuri Slobodyanyuk
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you
