Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
luca1994
New Contributor III

VPN SSL Autoban IP

Hello Team,

 

This is the scenario:

FGT firewall offering SSL VPN service
Is there any way to do these things?
1. Autoban IP same user wrong password 5 attempts over 10 minutes

2. Autoban IP different user wrong password 10 attempt over 30 minutes

 

Thanks for the support
BR

2 REPLIES 2
ozkanaltas
Valued Contributor III

Hello @luca1994 ,

 

Actually Fortigate does this automatically. But it just looks IP address of who tried. If a person has tried to login with the same IP address after 2 tries FortiGate will ban the IP address of the client for 60 seconds.

 

If you want, you can change this setting with these cli commands.

 

config vpn ssl settings
set login-attempt-limit 2
set login-block-time 60
end

 

If you want to take more specific action for a ban, you can use automation for that. It can follow the logs with automation and it can take action for you. 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
arahman
Staff
Staff

Hi, you can configure the automation stitch and do the same. as mentioned in the article below 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Block-SSL-VPN-failed-logins-with-an-automa...

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors