EU Radio Frequency Directive (RED) Cybersecurity Instruction Reference Guide

Password Brute Force Protection

If the web interface or CLI are exposed on the WAN network, brute-force attacks can be deployed repeatedly by malicious actors to gain illegitimate access to the firewall management functions. We recommend the following to mitigate the impact:

  1. Navigate to Device > Settings > Administration > Login/Multiple Administrators.

  2. Set Failed login attempts before lockout to 3 every 1 minute.
  3. Set a Lockout Period (mins) to 10.
  4. To configure multi-factor authentication for administrators, navigate to Device > Settings > Administration > Firewall Administrator.
  5. Go to the Administrator Name & Password section and select TOTP from the drop-down list in the One-time Passwords Method field.

  6. To restrict inbound HTTPS access to particular hosts or networks through a firewall access rule by allowing only known IP addresses to have access to the web interface via the intranet or internet:
    1. Navigate to Policy > Rules and Policies > Access Rules.
    2. Select +Add at the bottom of the screen.
    3. Create a rule that limits HTTPS Management access.