- Joined
- Sep 11, 2023
- Messages
- 360
- Reaction score
- 45
Hello everyone, I'd like to start by saying this is just a request. I'm aware of and use MFA authentication and IP address list console restrictions. Currently, however, if an internal account is attacked on the fifth incorrect password attempt from the same IP address, that IP address is blocked for 900 seconds (15 minutes). The event notification and external syslog do not indicate the account under attack, but simply state that the IP address xxx..xxx.xxx.xxx has been blocked for 900 seconds due to incorrect password attempts. Is there a way to block the IP address as well as the account itself by sending a notification?