cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
TomS
Level 7
Report Inappropriate Content
Message 1 of 2

Extend Admin lockout time

Jump to solution

Currently when entering an incorrect password too many times for the local admin I get the message "Logins currently blocked. Please wait a few seconds." However there either is no block at all, or the time out is no more than two seconds, as I can continue to paste in invalid passwords and get denied, or enter a valid password and get allowed in. I am using Web Gateway v10.2.5.

Is there a way to extend the admin lockout time?

 

Thanks 🙂

1 Solution

Accepted Solutions
fw_mon
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 2 of 2

Re: Extend Admin lockout time

Jump to solution

Hello @TomS 

I can confirm, I have a feeling that the UI just shows a popup window and you can repeat a login attempt right after closing the popup without any delay. It looks like a way to slow down brute force attempts by showing a poput that must be closed by click and no really delay is introduced between attempts.

As there are no delay thefore it seems there is no way to configure it. 

What you can is to monitor the audit.log for bruteforce attempts and react accordingly.

 

 

Timestamp  : 15/Nov/2022:20:03:24.674 -0600
User       : admin
Action     : USER_LOGIN_FAILED
Source Type: USER
Source ID  : 10.20.30.40
Appliance  : mwg
Details:
   User-Agent: Java/1.8.0_342
   Details : Logins blocked due to prior failed login.
Was my response useful to you? If so, please consider marking it as an Accepted Solution and giving it a Kudo (click on the thumb up symbol) to help other community members. MWG+Splunk=❤

View solution in original post

1 Reply
fw_mon
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 2 of 2

Re: Extend Admin lockout time

Jump to solution

Hello @TomS 

I can confirm, I have a feeling that the UI just shows a popup window and you can repeat a login attempt right after closing the popup without any delay. It looks like a way to slow down brute force attempts by showing a poput that must be closed by click and no really delay is introduced between attempts.

As there are no delay thefore it seems there is no way to configure it. 

What you can is to monitor the audit.log for bruteforce attempts and react accordingly.

 

 

Timestamp  : 15/Nov/2022:20:03:24.674 -0600
User       : admin
Action     : USER_LOGIN_FAILED
Source Type: USER
Source ID  : 10.20.30.40
Appliance  : mwg
Details:
   User-Agent: Java/1.8.0_342
   Details : Logins blocked due to prior failed login.
Was my response useful to you? If so, please consider marking it as an Accepted Solution and giving it a Kudo (click on the thumb up symbol) to help other community members. MWG+Splunk=❤
You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from product experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by employees.
Join the Community
Join the Community