Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
tanaki
New Contributor II

Fortigate VPN ban IPs

Hello,

Is there a   fail2ban-like  feature in Fortigate?   I'm running VPN server on my 60f and I want   it to block all  IPs with more than 3 failed login attempts

 

Thank you

3 REPLIES 3
gfleming
Staff
Staff

You can have your VPN terminated on a loopback and set up an IPS profile on the resulting FW policy that would be required.

Cheers,
Graham
Yurisk
SuperUser
SuperUser

Hi,

you don't really need fail2ban as there is a built-in feature for this in Fortigate:

 

CLI:

 

config vpn ssl settings

set login-attempt-limit [0-10] Default is 2.

set login-block-time [0-86400] Default is 60 seconds.

end

 

You can ban the failed logins IP for a duration of up to 24 hours.

 

Yuri Slobodyanyuk
Yuri Slobodyanyuk
tanaki
New Contributor II

Thank you

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors