Seeing some AnyConnect VPN rogue IP’s trying to connect this evening, not sure if they are actually making a connection into our firewall..?
example of log:
Dec 1 20:22:05 AnyConnect VPN AnyConnect VPN connection event msg: Local-IP[OUR MX95 WAN IP] Local-Port[443] Prot[TCP] Peer-IP[71.239.88.253] Peer-Port[51727] Conn-ID[9] TLSv1.2 connection established. Cipher: ECDHE-RSA-AES256-GCM-SHA384(49200)
Not seeing any actual AnyConnect VPN client connected that are suspicious, just these random TLSv1.2 attempts.
We have AnyConnect VPN enabled using SAML with DUO 2-factor setup for VPN allowed users.
thanks