Symantec VIP uses time-based One-Time Passwords (TOTP) to provide replay-resistant authentication. This article describes how to configure validation windows to maintain high security against replay attacks.
Symantec VIP is designed to be replay-resistant through the use of time-based One-Time Passwords (TOTP).
Because these codes are cryptographically bound to a specific time interval, a captured code cannot be used once that window has passed or the code has been successfully used by the validation service.
You can check and configure the credential time window within the VIP Manager Credential Security Settings:
Additionally, if using the VIP Enterprise Gateway, ensure the running version is 9.11 or later, as this version includes specific security enhancements for the management console's resistance to replay-style attacks (CSRF).