SSL VPN disconnect right after the connection

Options
Hello,

I have an USG Flex 100, configured as "on premises", I've created 2 users to access SSL VPN, at first everything was fine, but after one week the users couldn't connect anymore, tried to reinstall client but didn't solve the problem.
Looked the log in the USG and the error was "invalid username or password", so i've changed the password and it worked, but only for a few days, now I have to change user password each 1-3 days so the client can connect (the client is set to save password and as soon as I set a new one, works fine, so I guess it's not typing error).
Has anyone experienced this before?

Thanks

Accepted Solution

  • Zyxel_James
    Zyxel_James Posts: 626  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Answer ✓
    Options

    Hello @Ricardo_mnet
    Please check the logs or Password Changed Date to confirm if the password is changed by someone other than you, I suspect your admin account password has been leaked on the internet and the password was changed by someone else.

    To avoid this possible hacker behavior, please

    1. Delete user accounts that were not created by the network administrator and change all the current user's password

    2. Upgrade to the latest firmware

    3. To enhance web access login policy, please refer to this article

    If the issue still exists, please let me know, thank you.

    James

All Replies

  • Zyxel_James
    Zyxel_James Posts: 626  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Answer ✓
    Options

    Hello @Ricardo_mnet
    Please check the logs or Password Changed Date to confirm if the password is changed by someone other than you, I suspect your admin account password has been leaked on the internet and the password was changed by someone else.

    To avoid this possible hacker behavior, please

    1. Delete user accounts that were not created by the network administrator and change all the current user's password

    2. Upgrade to the latest firmware

    3. To enhance web access login policy, please refer to this article

    If the issue still exists, please let me know, thank you.

    James

Security Highlight