Cisco: VPN services facing password-spraying intrusions

BleepingComputer reports that numerous remote access VPN services were observed by Cisco to have been targeted by password-spraying attacks suspected to be part of a reconnaissance operation. Organizations should mitigate such attacks by activating remote syslog server logging, transferring unused default connection profiles to a sinkhole AAA server, and filtering unauthorized public IP addresses through control-plane ACL configurations, as well as using TCP shun and certificate-based RAVPN certification, according to Cisco.

Source: SC Magazine

 


Date:

Categorie(s):