VPN being used for malicious attacks

0

Hello!

I am a very novice customer and normally do not deal with VPN. However a couple of times now incidents have been identified where our team VPN has been used in probing/brute force attacks. For reference we allow BYoD and the VPN is used mainly for WorkDocs/Workmail access.

I have asked users to scan their devices for malicious soft to stop the attacks. However I need assistance with two issues: -how do I identify exactly which of my users' devices is the source of issue

  • is there a way to configure my VPN to prevent it from allowing similar brute force attacks from being carried out in the future?

Appreciate any assistance in advance.

1 Risposta
0

Not sure if you have tighten the firewall rules and security groups. To avoid it in future make sure you have open the required ports on firewall, along with security group.

you should check your LAN/office network too to make sure any malicious machine can not connect to network and should be quarantine immediately from rest of your network.

Check AWS best practice to avoid such incidents in future.

you might need to do some hard work.

Sachin
con risposta un anno fa

Accesso non effettuato. Accedi per postare una risposta.

Una buona risposta soddisfa chiaramente la domanda, fornisce un feedback costruttivo e incoraggia la crescita professionale del richiedente.

Linee guida per rispondere alle domande