Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
unknown1020
New Contributor III

brute force attacks in Fortigate

Good day friends.

due to constant news about large scale brute force campaigns targeting SSH devices targeting cisco, fortinet, checkpoint devices. What recommendations could be provided for FortiGate equipment?

3 REPLIES 3
adambomb1219
SuperUser
SuperUser

Same as any other vendor.  Do not enable admin access from the outside.  Use certificate based authentication, SAML, MFA, etc.

Marthen
New Contributor II

As mentioned brute force attack is coming for Tor then you can deny all incoming connections from Internet service Tor-Exit.Node  ( don't forget to check match-vip is enabled on deny policy).

hbac
Staff
Staff
Labels
Top Kudoed Authors