Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
tanaki
New Contributor II

Fortigate VPN ban IPs

Hello,

Is there a   fail2ban-like  feature in Fortigate?   I'm running VPN server on my 60f and I want   it to block all  IPs with more than 3 failed login attempts

 

Thank you

3 REPLIES 3
gfleming
Staff
Staff

You can have your VPN terminated on a loopback and set up an IPS profile on the resulting FW policy that would be required.

Cheers,
Graham
Yurisk
Valued Contributor

Hi,

you don't really need fail2ban as there is a built-in feature for this in Fortigate:

 

CLI:

 

config vpn ssl settings

set login-attempt-limit [0-10] Default is 2.

set login-block-time [0-86400] Default is 60 seconds.

end

 

You can ban the failed logins IP for a duration of up to 24 hours.

 

Yuri https://yurisk.info/  blog: All things Fortinet, no ads.
Yuri https://yurisk.info/ blog: All things Fortinet, no ads.
tanaki
New Contributor II

Thank you

Labels
Top Kudoed Authors