Can i Trust a IP for SSL VPN ( we keep haing to unlock user)
Options
Afternoon
We have 30 users in 1 x office all SSL VPN into a USG 310.
We have to regularly keep connecting to the router and perform "unlock lockout-users x.x.x.x"
The WAN IP of this office is static and never changes
Can we do something so this IP address is never locked out on a bad password?
Or maybe can we extent the lockout attenpts to a higher value?
0
All Replies
-
There is no IP white list for this.
But you can change lockout maximum retry by CLI Router(config)# users retry-count xx
BTW, assume branch office most users need to access HQ site resource, I strongly recommend install firewall on 2nd office to establish site to site VPN. With site to site VPN, users in branch no need to connect to HQ site individually.
0
Categories
- All Categories
- 442 Beta Program
- 3K Nebula
- 228 Nebula Ideas
- 130 Nebula Status and Incidents
- 6.6K Security
- 645 USG FLEX H Series
- 357 Security Ideas
- 1.8K Switch
- 86 Switch Ideas
- 1.4K Wireless
- 54 Wireless Ideas
- 7.1K Consumer Product
- 303 Service & License
- 496 News and Release
- 93 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.9K FAQ
- 34 Documents
- 89 About Community
- 110 Security Highlight
Freshman Member
Ally Member