<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Brute-Force Attack on Check Point Mobile VPN: Multiple IPs and Fake Usernames in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Brute-Force-Attack-on-Check-Point-Mobile-VPN-Multiple-IPs-and/m-p/255406#M42938</link>
    <description>&lt;P&gt;No&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk105740" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk105740&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 19 Aug 2025 11:27:17 GMT</pubDate>
    <dc:creator>CheckPointerXL</dc:creator>
    <dc:date>2025-08-19T11:27:17Z</dc:date>
    <item>
      <title>Brute-Force Attack on Check Point Mobile VPN: Multiple IPs and Fake Usernames</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Brute-Force-Attack-on-Check-Point-Mobile-VPN-Multiple-IPs-and/m-p/253937#M42652</link>
      <description>&lt;P&gt;I am experiencing a brute-force attack on my Check Point Mobile VPN access. The issue is that attackers are using a different IP address and username with each attempt, making it challenging to block them effectively. As shown in the second image, one IP (7.105.26.94.tbcg (94.26.105.7)) and username (zhall) were used only twice today, while the first image highlights the variety of IPs and usernames involved. I have SmartEvent Automatic Reaction configured, but the problem persists. Note that the usernames being used are not real usernames. I need advice on how to mitigate this.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jul 2025 09:03:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Brute-Force-Attack-on-Check-Point-Mobile-VPN-Multiple-IPs-and/m-p/253937#M42652</guid>
      <dc:creator>SubZer0</dc:creator>
      <dc:date>2025-07-25T09:03:04Z</dc:date>
    </item>
    <item>
      <title>Re: Brute-Force Attack on Check Point Mobile VPN: Multiple IPs and Fake Usernames</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Brute-Force-Attack-on-Check-Point-Mobile-VPN-Multiple-IPs-and/m-p/253960#M42655</link>
      <description>&lt;P&gt;There is no better way now to block this, as far as I know. This is part of having a portal with username / password that is accessible from the internet.&lt;/P&gt;
&lt;P&gt;The only thing I can recommend is to make sure fw is up to date. Have a good password policy and use 2FA.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can consider implementing geo protection, block some countries you don't have business with, this is not a solid solution but atleast decrease the amount of attacks.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jul 2025 12:39:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Brute-Force-Attack-on-Check-Point-Mobile-VPN-Multiple-IPs-and/m-p/253960#M42655</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-07-25T12:39:27Z</dc:date>
    </item>
    <item>
      <title>Re: Brute-Force Attack on Check Point Mobile VPN: Multiple IPs and Fake Usernames</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Brute-Force-Attack-on-Check-Point-Mobile-VPN-Multiple-IPs-and/m-p/253967#M42657</link>
      <description>&lt;P&gt;In SmartEvent is an option where you can block automatically after too many failed logins in a specified time frame.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jul 2025 14:08:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Brute-Force-Attack-on-Check-Point-Mobile-VPN-Multiple-IPs-and/m-p/253967#M42657</guid>
      <dc:creator>D_W</dc:creator>
      <dc:date>2025-07-25T14:08:36Z</dc:date>
    </item>
    <item>
      <title>Re: Brute-Force Attack on Check Point Mobile VPN: Multiple IPs and Fake Usernames</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Brute-Force-Attack-on-Check-Point-Mobile-VPN-Multiple-IPs-and/m-p/253970#M42658</link>
      <description>&lt;P&gt;Uhh that was this option was posted by the starter of this topic&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jul 2025 14:18:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Brute-Force-Attack-on-Check-Point-Mobile-VPN-Multiple-IPs-and/m-p/253970#M42658</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-07-25T14:18:51Z</dc:date>
    </item>
    <item>
      <title>Re: Brute-Force Attack on Check Point Mobile VPN: Multiple IPs and Fake Usernames</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Brute-Force-Attack-on-Check-Point-Mobile-VPN-Multiple-IPs-and/m-p/253971#M42659</link>
      <description>&lt;P&gt;Ah right haven‘t read carefully enough. Interestingly that worked for us. There are other SKs as well for mulitple failed vpn logins. Depending what kind of VPN is used.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jul 2025 14:22:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Brute-Force-Attack-on-Check-Point-Mobile-VPN-Multiple-IPs-and/m-p/253971#M42659</guid>
      <dc:creator>D_W</dc:creator>
      <dc:date>2025-07-25T14:22:23Z</dc:date>
    </item>
    <item>
      <title>Re: Brute-Force Attack on Check Point Mobile VPN: Multiple IPs and Fake Usernames</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Brute-Force-Attack-on-Check-Point-Mobile-VPN-Multiple-IPs-and/m-p/253972#M42660</link>
      <description>&lt;P&gt;Geo protection does not work in this case because of implied rules; you'd have to look at using&amp;nbsp;DOS/Rate Limiting Policy for that.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jul 2025 15:56:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Brute-Force-Attack-on-Check-Point-Mobile-VPN-Multiple-IPs-and/m-p/253972#M42660</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2025-07-25T15:56:01Z</dc:date>
    </item>
    <item>
      <title>Re: Brute-Force Attack on Check Point Mobile VPN: Multiple IPs and Fake Usernames</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Brute-Force-Attack-on-Check-Point-Mobile-VPN-Multiple-IPs-and/m-p/255406#M42938</link>
      <description>&lt;P&gt;No&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk105740" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk105740&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 11:27:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Brute-Force-Attack-on-Check-Point-Mobile-VPN-Multiple-IPs-and/m-p/255406#M42938</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2025-08-19T11:27:17Z</dc:date>
    </item>
  </channel>
</rss>

