Block source of repeat radius authentication failure in ISE
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-08-2024 06:23 PM
Good evening, is there a way to create a policy in ISE where it automatically adds the source IP address of repeat failed authentication attempts to a block list? If someone was running a dictionary attack against one of our VPN gateways (ASA), I would think there would be some way to add that IP in a block list automatically rather than just being sitting ducks?
- Labels:
-
AnyConnect
-
VPN
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-08-2024 10:40 PM
Hi Ricky,
I don't think there is a direct way of doing that from ISE, however, what you can do is configure FTD control plane ACL as mentioned in below post from Rob since I believe you might be looking at same failure logs.
https://integratingit.wordpress.com/2021/06/26/ftd-control-plane-acl/
If you find this useful, please mark it helpful and accept the solution.
