VPN being used for malicious attacks

0

Hello!

I am a very novice customer and normally do not deal with VPN. However a couple of times now incidents have been identified where our team VPN has been used in probing/brute force attacks. For reference we allow BYoD and the VPN is used mainly for WorkDocs/Workmail access.

I have asked users to scan their devices for malicious soft to stop the attacks. However I need assistance with two issues: -how do I identify exactly which of my users' devices is the source of issue

  • is there a way to configure my VPN to prevent it from allowing similar brute force attacks from being carried out in the future?

Appreciate any assistance in advance.

1 Answer
0

Not sure if you have tighten the firewall rules and security groups. To avoid it in future make sure you have open the required ports on firewall, along with security group.

you should check your LAN/office network too to make sure any malicious machine can not connect to network and should be quarantine immediately from rest of your network.

Check AWS best practice to avoid such incidents in future.

you might need to do some hard work.

Sachin
answered a year ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.

Guidelines for Answering Questions