This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SSL VPN locks user on failed password

Hi,

Using XGS 6500 with Sophos connect client (2.1/2.2). If someone mistypes their password just once whilst logging in to the VPN it locks the AD account. AD logs suggest 4 failed attempts by the firewall to authenticate against 2 domain controllers.

Is this a setting anywhere? Surely one failed attempt (0x0000234) should result in a rejected login?

I've not attempted to increase the domain setting for failed attempts before lockout but has anyone had any experience of this issue?



This thread was automatically locked due to age.
Parents Reply
  • One entry in the log viewer for authentication failure, multiple on the DCs as I mentioned. We've got 2 DCs configured on the firewall, and the bad pwd count is always the same, 3 on the first DC listed and one on the second. It's definitely trying both, but surely on a 6A (bad password) return code it should stop? Something isn't right.

    SFOS is 18.5.2 MR2 build 380.

Children