Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Network intelligence

Does XG currently have any ability to receive network intelligence reports from internal hosts? If our internal netscaler/OWA/SSH/etc server was seeing a lot of password guessing attempts from a given source IP, I would like the firewall to start blocking that IP. Basically a distributed fail2ban.

XG can block password guess attempts for its own services, but by definition can't reliably tell a failed SSH/SCP/SFTP login attempt from a good one when the service is on the internal network.

The API seems to be extensive enough that I could roll my own, but maybe such a thing already exists or is already being worked on for XG?

thanks

James



This thread was automatically locked due to age.