Lockout users by username or IP






Hello,
after reading another security idea I focused on how locking-out users with too much failed attempts really work.
Differently from my idea it does not lock the user while it lock its public IP
MY IDEA IS: add the choice in configure —> user group —> setting between locking by username provided and or by IP
this IMHO would be an advancement because:
- if you ban that it ip it might happen that you are banning even other users. scenario: 5 employees of the same company go to a conference, they need to connect to thei VPN, they all use the hotel's WiFi, the first users inserts the wrong password too many times, they are all stuck for 30 minuts (or the time set)
- an attacker can spoof it's IP every 5 attemps and apparently change it (via a vpn or whatever) and performe a brute force attack bypassing the lockout security settings
if one wants to be hyper protected i would leave the choice to block by IP and eventually by both
Comments
-
Right!
Blocking the IP address could be a bad decision. There could be employers working at an external location and they would all be blocked.0 -
Hi @QuiteSmart
Let me summarize this idea in short: You hope the "User Lockout Settings" not just block IP address, but also block the user/admin account that trying to login. Is it correct?
Zyxel Melen0 -
Hello @Zyxel_Melen thank you for your interest in my idea.
To be more precise not "also" but and/or that would be that the administrator can decide which behavior will occour when the threshold is reached:
- block the user for xx minutes (if the type user exists)
- block the IP for xx minutes
- block both user both ip for xx minutes
PS it is interesting to understand what would happen if the user "Melen" is currently connected to the VPN and an attacker tries to connect using that exact user but with wrong passoword(scenario where on the firewall an user is allowed to connect more than once at a time): if in this case Malen is locked would this affect the real Malen user already connected? Because this can turn into a DoS scenario
0 -
Thanks for the detail information. @QuiteSmart
We will monitor this idea's comments and votes for evaluation.
Zyxel Melen1
Categories
- All Categories
- 438 Beta Program
- 2.7K Nebula
- 188 Nebula Ideas
- 121 Nebula Status and Incidents
- 6.2K Security
- 454 USG FLEX H Series
- 303 Security Ideas
- 1.6K Switch
- 81 Switch Ideas
- 1.3K Wireless
- 44 Wireless Ideas
- 6.8K Consumer Product
- 278 Service & License
- 435 News and Release
- 88 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.2K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 91 Security Highlight