<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Blocking VPN users after so many unsuccessful connection attempts in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-VPN-users-after-so-many-unsuccessful-connection/m-p/239054#M2854</link>
    <description>&lt;P&gt;Could this be the solution:&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;sk182087 "How to prevent multiple unsuccessful login attempts from Endpoint Security Client users on a Security Gateway"&lt;BR /&gt;EDIT: Seems to be user based only...&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;HR /&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Mon, 20 Jan 2025 12:13:19 GMT</pubDate>
    <dc:creator>Arskazv</dc:creator>
    <dc:date>2025-01-20T12:13:19Z</dc:date>
    <item>
      <title>Blocking VPN users after so many unsuccessful connection attempts</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-VPN-users-after-so-many-unsuccessful-connection/m-p/232464#M2844</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;
&lt;P&gt;I read couple of posts people ask about this in the past, but does not appear there was a concrete answer. Is there any possible way to block a user after they fail connecting to vpn after so many attempts? I know SAM rules are used to instantly block specific IP addresses, but that wont do for a user.&lt;/P&gt;
&lt;P&gt;So, here is basic example...say user fails to authenticate to VPN site after 3 attempts, can admin block them for an hour before they can try again?&lt;/P&gt;
&lt;P&gt;Thanks as always.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2024 16:03:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-VPN-users-after-so-many-unsuccessful-connection/m-p/232464#M2844</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-12T16:03:27Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking VPN users after so many unsuccessful connection attempts</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-VPN-users-after-so-many-unsuccessful-connection/m-p/232484#M2845</link>
      <description>&lt;P&gt;The only way I could see doing this is with an automatic reaction in SmartEvent.&lt;BR /&gt;Whether it's actually possible is a separate question.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2024 20:35:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-VPN-users-after-so-many-unsuccessful-connection/m-p/232484#M2845</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-11-12T20:35:05Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking VPN users after so many unsuccessful connection attempts</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-VPN-users-after-so-many-unsuccessful-connection/m-p/232485#M2846</link>
      <description>&lt;P&gt;Thank you, appreciate the feedback as always!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2024 20:37:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-VPN-users-after-so-many-unsuccessful-connection/m-p/232485#M2846</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-12T20:37:31Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking VPN users after so many unsuccessful connection attempts</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-VPN-users-after-so-many-unsuccessful-connection/m-p/232510#M2847</link>
      <description>&lt;P&gt;What is authentication method of user in question ? Simple (&lt;A href="https://support.checkpoint.com/results/sk/sk182336" target="_blank" rel="noopener"&gt;not secured&lt;/A&gt;) username/password ?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2024 23:23:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-VPN-users-after-so-many-unsuccessful-connection/m-p/232510#M2847</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2024-11-12T23:23:54Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking VPN users after so many unsuccessful connection attempts</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-VPN-users-after-so-many-unsuccessful-connection/m-p/232511#M2848</link>
      <description>&lt;P&gt;In this case, yes, but I was more asking generally, regardless of what auth method is.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2024 23:36:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-VPN-users-after-so-many-unsuccessful-connection/m-p/232511#M2848</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-12T23:36:08Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking VPN users after so many unsuccessful connection attempts</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-VPN-users-after-so-many-unsuccessful-connection/m-p/232517#M2849</link>
      <description>&lt;P&gt;Hi Andy,&lt;/P&gt;
&lt;P&gt;Not sure if it relates, but I know we have such feature for SNX but for IP addresses (not users).&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk180271" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk180271&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Also I think PhoneBoy mentioned before in a different thread about using Gaia OS passwords as authentication to lockout users after failed login attempts.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Remote-Access-VPN/Remote-VPN-User-account-lock-after-failed-authentication/m-p/33828#M1263" target="_blank"&gt;https://community.checkpoint.com/t5/Remote-Access-VPN/Remote-VPN-User-account-lock-after-failed-authentication/m-p/33828#M1263&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2024 00:51:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-VPN-users-after-so-many-unsuccessful-connection/m-p/232517#M2849</guid>
      <dc:creator>Tom_Hinoue</dc:creator>
      <dc:date>2024-11-13T00:51:06Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking VPN users after so many unsuccessful connection attempts</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-VPN-users-after-so-many-unsuccessful-connection/m-p/232518#M2850</link>
      <description>&lt;P&gt;Thanks Tom! Yes, I had seen that post before by Phoneboy, but sadly its not related to this exact scenario. Now, sk you mentioned, looks super interesting. I wonder if doing fw ctl set -f flag for below kernel parameter may actually work, definitely worth a try.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;vpn_failed_auth_attempt_threshold&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Thanks a lot again, I value the advice.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2024 00:56:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-VPN-users-after-so-many-unsuccessful-connection/m-p/232518#M2850</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-13T00:56:20Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking VPN users after so many unsuccessful connection attempts</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-VPN-users-after-so-many-unsuccessful-connection/m-p/232583#M2851</link>
      <description>&lt;P&gt;Hey again Tom,&lt;/P&gt;
&lt;P&gt;I will have a call today with my colleague and bring up this kernel parameter setting and see if client would be okay to test this out. I dont think it should be an issue, as they are smaller shop, so probably not a big hurdle, if you will, to try.&lt;/P&gt;
&lt;P&gt;Will keep you posted. Thanks a lot again for sending this, I feel really positive about it, as setting certainly does make sense.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2024 14:19:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-VPN-users-after-so-many-unsuccessful-connection/m-p/232583#M2851</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-13T14:19:35Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking VPN users after so many unsuccessful connection attempts</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-VPN-users-after-so-many-unsuccessful-connection/m-p/232599#M2852</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8345"&gt;@Tom_Hinoue&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sadly, did not work. Tested in the lab, but no joy. I believe its only applicable to snx, NOT vpn client.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[Expert@R82:0]# fw ctl set -f int vpn_failed_auth_attempt_threshold 5&lt;BR /&gt;"fwkern.conf" was updated successfully&lt;BR /&gt;[Expert@R82:0]# more /opt/CPsuite-R82/fw1/boot/modules/fwkern.conf&lt;BR /&gt;udp_is_verify_cksum=0&lt;BR /&gt;vpn_failed_auth_attempt_threshold=5&lt;BR /&gt;[Expert@R82:0]#&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2024 15:27:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-VPN-users-after-so-many-unsuccessful-connection/m-p/232599#M2852</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-13T15:27:07Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking VPN users after so many unsuccessful connection attempts</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-VPN-users-after-so-many-unsuccessful-connection/m-p/239053#M2853</link>
      <description>&lt;P&gt;I'd also like some built in solution (similar the one for SNX clients) for VPN clients. Bruteforcing of VPN users/passwords has increased last years.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2025 12:06:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-VPN-users-after-so-many-unsuccessful-connection/m-p/239053#M2853</guid>
      <dc:creator>Arskazv</dc:creator>
      <dc:date>2025-01-20T12:06:08Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking VPN users after so many unsuccessful connection attempts</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-VPN-users-after-so-many-unsuccessful-connection/m-p/239054#M2854</link>
      <description>&lt;P&gt;Could this be the solution:&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;sk182087 "How to prevent multiple unsuccessful login attempts from Endpoint Security Client users on a Security Gateway"&lt;BR /&gt;EDIT: Seems to be user based only...&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;HR /&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Mon, 20 Jan 2025 12:13:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-VPN-users-after-so-many-unsuccessful-connection/m-p/239054#M2854</guid>
      <dc:creator>Arskazv</dc:creator>
      <dc:date>2025-01-20T12:13:19Z</dc:date>
    </item>
  </channel>
</rss>

