RE: How to secure Nav - bruteforce etc?
hi,
this is very huge area....
for the basic you can do ,,,,
1.Requiring users to create complex passwords
2.Limiting the number of times a user can unsuccessfully attempt to log in
3.Temporarily locking out users who exceed the specified maximum number of failed login attempts
4.set ideal timeout
but this is not enough by technically (you must have some network filters (eg : barakuda/watchguard) let the network admins to handle it '
other thing is identify your requirement and clients why need to log NAV directly..
if you really want you can open tunnel / vpn for them
there are various why and if you able to tell us more details about why your clients need to log by out side and what are the function they need to do on out side , we can make you more suggestion