Stop illegal login attempts?



Hi,

How can I stop illegal login attempts to my SBS box Exchange server?
This is on SBS 2003 SP1.
I had a guy last night try for over 3 hours to guess my username/password
which generated over 610 security errors in the security event log.
My server is behind a nat router (Zywall35) so I did capture the persons IP
from Romania.
However, is there not a way to lock out repeated attempts that occur in
rapid succesion?
I know I can do such with the router but I'd rather learn how to do such
with built in SBS or Exchange tools if possible.

I've copied and pasted a typical event log from these attempts below.
Of course the user name field was different for each attempt this person
made.
Looks like a typical dictionary attack to me but how to block this after say
10 attempts?

Any advice is welcome!

Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 529
Date: 11/26/2006
Time: 23:53:43
User: NT AUTHORITY\SYSTEM
Computer: WX98
Description:
Logon Failure:
Reason: Unknown user name or bad password
User Name: Beaner
Domain:
Logon Type: 3
Logon Process: Advapi
Authentication Package: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Workstation Name: WX98
Caller User Name: WX98$
Caller Domain: KRUSEONE
Caller Logon ID: (0x0,0x3E7)
Caller Process ID: 784
Transited Services: -
Source Network Address: -
Source Port: -


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.


.



Relevant Pages

  • Re: Wrong domain in event log?
    ... The failed login was from the workstation called BCCIJHINSLEY at IP address ... Les Connor [SBS Community Member - SBS MVP] ... Logon Failure: ... Caller User Name: - ...
    (microsoft.public.windows.server.sbs)
  • Re: Stop illegal login attempts?
    ... How can I stop illegal login attempts to my SBS box Exchange server? ... I had a guy last night try for over 3 hours to guess my username/password which generated over 610 security errors in the security event log. ... Logon Failure: ... Caller User Name: WX98$ ...
    (microsoft.public.windows.server.sbs)
  • Re: Error Code 537
    ... Kerberos authentication issues are most often as a result of a time ... Les Connor [SBS Community Member - SBS MVP] ... > Logon Failure: ... > Caller User Name: - ...
    (microsoft.public.windows.server.sbs)
  • Re: Last SBS request for a while... I promise!
    ... With regards to OWA not authenticating, I'm getting the following Failure ... Logon Failure: ... Workstation Name: SBS ... Caller User Name: SBS$ ...
    (microsoft.public.windows.server.sbs)
  • Re: How do increase security?
    ... Les Connor [SBS Community Member - SBS MVP] ... Logon Failure: ... Workstation Name: SERVER ... Caller User Name: SERVER$ ...
    (microsoft.public.windows.server.sbs)