Can i Trust a IP for SSL VPN ( we keep haing to unlock user)
Options
Afternoon
We have 30 users in 1 x office all SSL VPN into a USG 310.
We have to regularly keep connecting to the router and perform "unlock lockout-users x.x.x.x"
The WAN IP of this office is static and never changes
Can we do something so this IP address is never locked out on a bad password?
Or maybe can we extent the lockout attenpts to a higher value?
0
All Replies
-
There is no IP white list for this.
But you can change lockout maximum retry by CLI Router(config)# users retry-count xx
BTW, assume branch office most users need to access HQ site resource, I strongly recommend install firewall on 2nd office to establish site to site VPN. With site to site VPN, users in branch no need to connect to HQ site individually.
0
Categories
- All Categories
- 442 Beta Program
- 2.9K Nebula
- 220 Nebula Ideas
- 128 Nebula Status and Incidents
- 6.5K Security
- 606 USG FLEX H Series
- 344 Security Ideas
- 1.7K Switch
- 84 Switch Ideas
- 1.4K Wireless
- 52 Wireless Ideas
- 7K Consumer Product
- 298 Service & License
- 482 News and Release
- 92 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.8K FAQ
- 34 Documents
- 87 About Community
- 105 Security Highlight
Freshman Member
Ally Member