When checking the logs of my Harmony Connect VPN service I can see that there is a couple of IPs address coming from Ukraine that are generating 75% of my logs.
Are you experiencing the same?
Last week I reported the same incident but from two different IPs as well from Ukraine and looks to me that the TAC people helped me out to block them. last IP: 109.207.200.44
If you check your Harmony Connect VPN logs, can you see them too?
I understand the part of: they do not have the keys, or certificate and etc to break in, yeah, but those IPS are saturating Check Point logs and probably even degrading the service.
Does anyone know how to block them with involving TAC? I already added a policy that blocks any access from those IPs and nothing actually happened because I think it only applies to the valid traffic inside the VPN.
An email was sent today to the organization in Ukraine that are in charge of those IPs. nothing might happen!
Thoughts?
Regards,
Oscar Catana
https://ipthub.com
Cyber Sec Passionate!