cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Who Me Too'd this topic

block ip addresses that try to brute force into VPN

mikeyasg
Level 1
Level 1

Hello,

Starting from the last three weeks these IP Addresses are attempting to VPN into our network. In the ISE LiveLogs we can see that there are multiple attempts from these ip addresses. These IP addresses were added to the prefilter block rule on the FTD firewall. But still the authentication traffic is reaching the ISE server. shouldn't it be blocked the firewall. 

Any ideas why this address is still able to attempt auth, even though it should be getting denied before it even gets that far?

Screenshot 2023-04-27 152407.png 

Who Me Too'd this topic