Our fortigate 60e firewall has a few logs from our VPN over the weekend which are
[ul]and after looking at the remote IP it shows they are based in China, which isnt any of our users. I just wondered is this common and what can be done to prevent it?
We use to connect to the VPN via an IP address but we recently setup a domain (vpn.domain.com) so it matches our ssl cert and so we dont get the SSL certificate warning. I wonder if somehow these hackers are finding domains with vpn.domain.com and trying to connect?
The strange thing is there was no failed or successful login attempt just SSL exit error? We have 2 factor auth setup so theres no way anyone could get on either so pretty sure its ok but wanted to check with the fortigate pros?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1748 | |
1114 | |
765 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.