Mar 16 16:06:58 SRC=193.149.180.45 PROTO=TCP SPT=52416 DPT=1723 SYN
Mar 16 16:06:59 SRC=193.149.180. ...
show moreMar 16 16:06:58 SRC=193.149.180.45 PROTO=TCP SPT=52416 DPT=1723 SYN
Mar 16 16:06:59 SRC=193.149.180.45 PROTO=TCP SPT=52416 DPT=1723 SYN
Mar 16 16:07:01 SRC=193.149.180.45 PROTO=TCP SPT=52416 DPT=1723
...
show less
Port Scan
Anonymous
Still trying brute-force, now with other usernames!
Message meets Alert condition
The following cr ...
show moreStill trying brute-force, now with other usernames!
Message meets Alert condition
The following critical firewall event was detected: SSL VPN login fail.
date=2023-02-22 time=08:25:00 devname=XXXXXXXXXX devid=XXXXXXXXXX eventtime=1677072300968377930 tz="-0500" logid="0101039426" type="event" subtype="vpn" level="alert" vd="root" logdesc="SSL VPN login fail" action="ssl-login-fail" tunneltype="ssl-web" tunnelid=0 remip=193.149.180.45 user="windows/exchange" group="N/A" dst_host="N/A" reason="sslvpn_login_permission_denied" msg="SSL user failed to logged in"
show less
Port Scan
Hacking
Brute-Force
Anonymous
User at this IP address clearly testing for FortiGate SSL-VPN vulerabilities, multiple brute-force a ...
show moreUser at this IP address clearly testing for FortiGate SSL-VPN vulerabilities, multiple brute-force attempts.
The following critical firewall event was detected: SSL VPN login fail.
date=2023-02-21 time=06:14:03 devname=XXXXX devid=XXXXXX eventtime=1676978043091314810 tz="-0500" logid="0101039426" type="event" subtype="vpn" level="alert" vd="root" logdesc="SSL VPN login fail" action="ssl-login-fail" tunneltype="ssl-web" tunnelid=0 remip=193.149.180.45 user="adminlaw/finance/guest" group="N/A" dst_host="N/A" reason="sslvpn_login_permission_denied" msg="SSL user failed to logged in"
show less