This forum is closed to new posts and responses. Individual names altered for privacy purposes. The information contained in this website is provided for informational purposes only and should not be construed as a forum for customer support requests. Any customer support requests should be directed to the official HCL customer support channels below:

HCL Software Customer Support Portal for U.S. Federal Government clients
HCL Software Customer Support Portal


May 4, 2015, 2:40 PM
45 Posts

Alternative to Internet Password Lockout database?

  • Category: Mail
  • Platform: Windows
  • Release: 9.0.1
  • Role:
  • Tags:
  • Replies: 8

The Internet Password Lockout database, by locking out user accounts rather than IP addresses, is working wonderfully at p*ssing off users.

Is there an alternative?

May 4, 2015, 3:05 PM
212 Posts
Internet password security

If you do not like the default internet passowrd lockout settings, you can configure those settings to a more acceptable level by creating a security policy.  Look in you IBM Domino Administrator Client Help file for information on how to creat the policy if you are not familiar on how to do this.

May 4, 2015, 6:55 PM
9 Posts
Creating a Policy with regards to IP lockout

I'm having the same difficulty and would like to see a how to as opposed to a "go to the help files."  Has anyone had success in implementing an IP lockout vs. user lockout?

 

EDIT:  I just sent the following to IBM support on a newly created PMR.

Since there seems no way from stopping a "Brute Force Attack" on our mail server other than locking the user out after a number of tries....  Is there any way that the Internet Security Policy can be used to lockout offending IP's rather than users or a combination of both?

For example:
an offending IP address that unsuccessfully  tries to login more than 3 times is locked out.
However, the user account remains unlocked and can successfully login from a different IP address.

 

May 4, 2015, 7:12 PM
45 Posts
Internet Password Lockout is really lame

Agreed, al de la cruz. Users are finding how it works a real turn off, as in, a show stopper turn off and you get my drift.

May 5, 2015, 12:44 PM
45 Posts
Policy doesn't help

Bradley, I looked at Policy in case I'd missed over the years there options for IP lockout, but nope, all it does is present you options for locking out user accounts. Or did I miss something?

Feb 6, 2017, 12:01 PM
19 Posts
Is there a solution yet?

guys kinda stuck here with same brute attack issue Is there a  solution yet?

 

Feb 6, 2017, 4:43 PM
3 Posts
Use an OS based solution

Hi,

  Sometime ago we tried to solve the same issue. We used the information publish at our web site.

  If the attacks are quite frequent you should also have to "clean" the blocked IPs, as I don't know which Window 2002 limit is for the field that stores the blocked IPs. In any case, as a good practice, this solution should be extended to block the IPs at the firewall level and not at the local Server.

 

Feb 7, 2017, 4:32 AM
19 Posts
We have linux based installation

Hi Migeul,

We have linux based domino.

As suggested will try os/ FW based solution.

Thanks

 

Feb 8, 2017, 10:39 AM
19 Posts
Firewall IPS signature.

Hi all,

There is an IPS signature for brute on smtp.

 

Did the trick.

Thanks


This forum is closed to new posts and responses. Individual names altered for privacy purposes. The information contained in this website is provided for informational purposes only and should not be construed as a forum for customer support requests. Any customer support requests should be directed to the official HCL customer support channels below:

HCL Software Customer Support Portal for U.S. Federal Government clients
HCL Software Customer Support Portal