VPN being used for malicious attacks

0

Hello!

I am a very novice customer and normally do not deal with VPN. However a couple of times now incidents have been identified where our team VPN has been used in probing/brute force attacks. For reference we allow BYoD and the VPN is used mainly for WorkDocs/Workmail access.

I have asked users to scan their devices for malicious soft to stop the attacks. However I need assistance with two issues: -how do I identify exactly which of my users' devices is the source of issue

  • is there a way to configure my VPN to prevent it from allowing similar brute force attacks from being carried out in the future?

Appreciate any assistance in advance.

1 Respuesta
0

Not sure if you have tighten the firewall rules and security groups. To avoid it in future make sure you have open the required ports on firewall, along with security group.

you should check your LAN/office network too to make sure any malicious machine can not connect to network and should be quarantine immediately from rest of your network.

Check AWS best practice to avoid such incidents in future.

you might need to do some hard work.

Sachin
respondido hace un año

No has iniciado sesión. Iniciar sesión para publicar una respuesta.

Una buena respuesta responde claramente a la pregunta, proporciona comentarios constructivos y fomenta el crecimiento profesional en la persona que hace la pregunta.

Pautas para responder preguntas