Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
SubZer0
Contributor

Brute-Force Attack on Check Point Mobile VPN: Multiple IPs and Fake Usernames

I am experiencing a brute-force attack on my Check Point Mobile VPN access. The issue is that attackers are using a different IP address and username with each attempt, making it challenging to block them effectively. As shown in the second image, one IP (7.105.26.94.tbcg (94.26.105.7)) and username (zhall) were used only twice today, while the first image highlights the variety of IPs and usernames involved. I have SmartEvent Automatic Reaction configured, but the problem persists. Note that the usernames being used are not real usernames. I need advice on how to mitigate this.

 

 

0 Kudos
6 Replies
Lesley
Authority Authority
Authority

There is no better way now to block this, as far as I know. This is part of having a portal with username / password that is accessible from the internet.

The only thing I can recommend is to make sure fw is up to date. Have a good password policy and use 2FA. 

You can consider implementing geo protection, block some countries you don't have business with, this is not a solid solution but atleast decrease the amount of attacks. 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
CaseyB
Advisor

Geo protection does not work in this case because of implied rules; you'd have to look at using DOS/Rate Limiting Policy for that.

0 Kudos
CheckPointerXL
Advisor
Advisor

0 Kudos
D_W
Advisor

In SmartEvent is an option where you can block automatically after too many failed logins in a specified time frame.

0 Kudos
Lesley
Authority Authority
Authority

Uhh that was this option was posted by the starter of this topic

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
D_W
Advisor

Ah right haven‘t read carefully enough. Interestingly that worked for us. There are other SKs as well for mulitple failed vpn logins. Depending what kind of VPN is used.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events