<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSH Brute Force in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/ssh-brute-force/m-p/576473#M2089</link>
    <description>&lt;P&gt;Client connects to FTP server via SSH and starts downloading. After a while, connection stops. I see in the logs that there a multiple SSH login attempts and finally SSH Brute Force with reset-both action.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What would be the reason?&lt;/P&gt;</description>
    <pubDate>Wed, 07 Feb 2024 15:58:31 GMT</pubDate>
    <dc:creator>HyAz45</dc:creator>
    <dc:date>2024-02-07T15:58:31Z</dc:date>
    <item>
      <title>SSH Brute Force</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/ssh-brute-force/m-p/576473#M2089</link>
      <description>&lt;P&gt;Client connects to FTP server via SSH and starts downloading. After a while, connection stops. I see in the logs that there a multiple SSH login attempts and finally SSH Brute Force with reset-both action.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What would be the reason?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2024 15:58:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/ssh-brute-force/m-p/576473#M2089</guid>
      <dc:creator>HyAz45</dc:creator>
      <dc:date>2024-02-07T15:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Brute Force</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/ssh-brute-force/m-p/576575#M2090</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/299531"&gt;@HyAz45&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is happening because you have vulnerability protection profile configured on the security policy which is matching the traffic. This signature is triggered when there are multiple requests for this traffic constantly from same source to the same destination. If you are expecting all such requests as valid, then you can exclude specific source or destination IP from this signature. Refer &lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/threat-prevention/customize-the-action-and-trigger-conditions-for-a-brute-force-signature" target="_self"&gt;this article&lt;/A&gt; for more details.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope it helps!&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 07:48:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/ssh-brute-force/m-p/576575#M2090</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2024-02-08T07:48:14Z</dc:date>
    </item>
  </channel>
</rss>

