05-15-2025
07:32 PM
- last edited on
05-15-2025
07:58 PM
by
shaiksh
Dear Team,
We are looking the stable FTD version can upgrade to fixed the vulnerability and ensure it cover suck of attack like VPN brute force...and prevent AD Account locked out even attacker known the legit AD user.
Kindly share commend / good practice to resolve it.
Best Regards,
Solved! Go to Solution.
05-15-2025 11:13 PM
@Da ICS16 the threat detection feature for remote access VPN services helps prevent Denial of Service (DoS) attacks and is supported in the following releases.
These threat detection features are supported in the Cisco Secure Firewall Threat Defense versions listed next:
7.4.2 is the current Cisco gold star version.
05-15-2025 11:13 PM
@Da ICS16 the threat detection feature for remote access VPN services helps prevent Denial of Service (DoS) attacks and is supported in the following releases.
These threat detection features are supported in the Cisco Secure Firewall Threat Defense versions listed next:
7.4.2 is the current Cisco gold star version.
05-15-2025 11:24 PM
Hello @Rob Ingram Thanks for helpful commend.
05-19-2025 11:15 PM
Hello @Rob Ingram
Cisco TAC is also recommended to upgrade to the current cisco golden star version. Did you tested and resolve the case from vpn bruteforce? thanks,
05-19-2025 07:11 AM
I have found that changing your VPN login URL to a non-default value (e.g., vpn.company.com/corp instead of simply vpn.company.com) and sending the defaultWebVPN profile to a non-existent AAA server is the best protection against these attacks.
05-19-2025 07:09 PM - edited 05-19-2025 11:16 PM
Hello @Marvin Rhoads
Thanks for commend. it is the workaround solution? Could you share doc/url me to review?
Best Regards,
05-20-2025 05:09 AM
@Da ICS16 it's this solution:
Basically, valid users' profiles point to a non-published group-url. They use your legitimate authentication method. Non-legitimate users that try to go the the default profile are directed to either a. use certificates (which they won't have) or to a "sinkhole" (invalid) AAA server which will never authenticate them (nor affect any legitimate users' accounts).
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide