- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SSL VPN issues on my E61
So, I have an E61 firewall and it's got a nice SSL VPN on it for my 10 or so users who are in other countries. These users connect and we are using an LDAP integration for authentication.
Today, I found out that people are trying to access the SSL VPN using real usernames from the org, and when they enter the wrong password three times, the user is locked out of Active Directory.
For now, the SSL VPN is disabled.
I need a solution for this.
My first thought is to get some tokens and enable 2FA.
Can some of you experts make some suggestions about how to best mitigate this?
Thanks
Solved! Go to Solution.
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I opened a ticket with FG and they recommended the dialup SSL VPN using a preshared key.
I opted for 40 tokens and turning on 2FA.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This is Googles answer when I searched with "windows AD lockout after three failed attempts". You can get the same yourself.
Security measure:
Access Group Policy:
Considerations:
Toshi
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you Toshi.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I opened a ticket with FG and they recommended the dialup SSL VPN using a preshared key.
I opted for 40 tokens and turning on 2FA.
