Hello @TomS
I can confirm, I have a feeling that the UI just shows a popup window and you can repeat a login attempt right after closing the popup without any delay. It looks like a way to slow down brute force attempts by showing a poput that must be closed by click and no really delay is introduced between attempts.
As there are no delay thefore it seems there is no way to configure it.
What you can is to monitor the audit.log for bruteforce attempts and react accordingly.
Timestamp : 15/Nov/2022:20:03:24.674 -0600
User : admin
Action : USER_LOGIN_FAILED
Source Type: USER
Source ID : 10.20.30.40
Appliance : mwg
Details:
User-Agent: Java/1.8.0_342
Details : Logins blocked due to prior failed login.
Was my response useful to you? If so, please consider marking it as an Accepted Solution and giving it a Kudo (click on the thumb up symbol) to help other community members. MWG+Splunk=❤