12-19-2018 03:52 AM
Hello folks,
One of our customers is saying that, when implementing Multiple Failure Login attempts (configured to 3) it gets shun by 20 minutes. However, if using a different laptop, within the 20min range, same user can login with right password.
This, naturally, makes us think that the shun criteria is based on MAC-Address, and not on the Guest name.
This opens space (thinking of Audit) to saying that you can easily spoof the MAC-Address to bypass the "Maximum failed login attempts before rate limiting" feature.
Any comments?
Solved! Go to Solution.
12-19-2018 07:14 AM
12-19-2018 06:44 AM
If MAC spoof is an issue, then please put additional security in place and not rely solely on MAC-based authentication.
12-19-2018 07:14 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide