Block Brute Force VPN Attack by Username - possible?

Split tunnel with DNS through VPN. We have a few hundred rules so it’d be easier to add the loop back to existing rules vs cloning. So I do a VIP to the loopback? I’ll have to rewatch this more.ty