Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
sam653
New Contributor

SSLVPN failed user login attempts constantly been seen

Hello,

 

I am seeing constant alerts on my Fortigate under sslvpn events "sslvpn login failed"

 

This is not coming from the authorized users. Is there anything that can be done on it.

 

 

Thanks

1 Solution
sprashant
Staff
Staff

Hello @sam653 

 

You can refer to following resource:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGate-SSL-VPN-best-practices-guide/ta-...

 

This will walk you over the steps to strengthen the SSL VPN

Sprashant

View solution in original post

5 REPLIES 5
sprashant
Staff
Staff

Hello @sam653 

 

You can refer to following resource:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGate-SSL-VPN-best-practices-guide/ta-...

 

This will walk you over the steps to strengthen the SSL VPN

Sprashant
hjhajj
Staff
Staff

Hello @sam653 

In  addition to the  above  given  document, Kindly also refer to the following document which explains how to secure and limit an SSL VPN unknown user login

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-secure-and-limit-an-SSL-VPN-unknown...

Thanks and Regards,
Harmandeep Kaur Jhajj

 

Sgagan
Staff
Staff

Greetings @sam653 

You can also configure an automation stitch in order to permanently block failed login attempts:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-permanently-block-SSL-VPN-failed-lo...

GD
vbandha
Staff
Staff

Hello @sam653 

One other option to block these attempts is via local in policy.

 

With local in policy the attempt is blocked before any processing is done by fortigate so this will not generate any logs. 

Here is an article with more information on this:

https://docs.fortinet.com/document/fortigate/6.2.16/cookbook/363127/local-in-policies

 

You can use geo location address object in source if the attempts are coming from specific countries:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-block-by-country-or-geolocation/ta-...

 

Regards,

Varun

FortiArt
Staff
Staff

Try to use ZTNA rather than sslvpn as this is more secure as per:

 

https://docs.fortinet.com/document/fortigate/7.0.0/new-features/194961/basic-ztna-configuration

 

Hope this help

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors