- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-27-2011 02:42 PM
In addition to dropping packets of an attacker (say the RDP Brute Force which I get a lot of), is it possible to auto-blacklist the attacker IP address after a certain number of attempts? It would then block all traffic from that source?
10-09-2011 04:04 AM
Hi,
Actually for brute force attack you can choose blockIP as the action after several failed attempts. You can setup the no.opf failed attempts within what interval that should trigger the block IP by clicking on the icon next to the vul sig name under object-> vulnerability.
Regards,
Jones
09-30-2011 11:36 AM
This is not possible. We do a feature in the NETWORK tab called "Zone Protection" where you can set thresholds for generating alerts as well as when to start dropping packets.
Steve Krall
10-09-2011 04:04 AM
Hi,
Actually for brute force attack you can choose blockIP as the action after several failed attempts. You can setup the no.opf failed attempts within what interval that should trigger the block IP by clicking on the icon next to the vul sig name under object-> vulnerability.
Regards,
Jones
11-07-2011 07:55 AM
Sorry, I can't find that option. When I go to objects, there is no "vulnerabilities" listed on the left menu. I am running PAN OS 4.0.5. I have Vulnerability Protection under Security Profiles, but that doesn't let me look at each individual vulnerability. There is Vulnerability under Custom Profiles but that is blank. I recall somewhere seeing the complete list of vulnerabilities, but I can't find it...
11-07-2011 09:38 AM
On the vulnerability protection profile, click custom instead of simple, and you will be able to see all vulnerability signatures. You can filter on just brute force attacks by typing in "brute". You can find the signature that you want and change the action to block-ip. You can setup the amount of time that you want to block all new traffic, and if you want it based on the source IP only or both source and destination IP. Additionally, you can customize the brute force attack thresholds by clicking on the pencil icon next to the signature name.
Alfred
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!