<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSH Login attempts with Root account from external IPs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-login-attempts-with-root-account-from-external-ips/m-p/125057#M46389</link>
    <description>&lt;P&gt;To add to this if you are remotely managing these devices then I would highly recommend setting a management profile that strictly limits the amount of IP addresses that can actually manage this device. That way you can not only be secure in knowing that nobody can just login to your device but they won't even see the login page or get access to the devices management if they don't have the set IP addresses.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 08 Nov 2016 19:12:22 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2016-11-08T19:12:22Z</dc:date>
    <item>
      <title>SSH Login attempts with Root account from external IPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-login-attempts-with-root-account-from-external-ips/m-p/119118#M45764</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can we block SSH login attempts (With root account )which are made from external IPs in Paloalto.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note: We also have customers who login from external Ips. We dont have customer Ip list to white list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and Regards.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2016 05:53:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-login-attempts-with-root-account-from-external-ips/m-p/119118#M45764</guid>
      <dc:creator>Shyam01</dc:creator>
      <dc:date>2016-10-14T05:53:12Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Login attempts with Root account from external IPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-login-attempts-with-root-account-from-external-ips/m-p/119119#M45765</link>
      <description>&lt;P&gt;enabling an ACL would be preferable, but if this is not possible: to prevent exposing your management interface to the internet, you could set up GlobalProtect connections for your customers that need access to thte management interface&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;that way they'll first need to VPN into the device before they cn connect to management, which is much safer&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;obfuscation can also help, by enabling the management profile on a loopback interface, and then setting up a Port Address Translation policy that translates, for example, your public IP's port 22222 to the loopback internal port 22&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2016 06:27:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-login-attempts-with-root-account-from-external-ips/m-p/119119#M45765</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-10-14T06:27:41Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Login attempts with Root account from external IPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-login-attempts-with-root-account-from-external-ips/m-p/124895#M46376</link>
      <description>&lt;P&gt;Thank you for the information. Could you kindly provide detail information on second point or provide the referense site to undastand.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note: As I said before, we dont have customer IPs list to whitelist.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2016 09:32:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-login-attempts-with-root-account-from-external-ips/m-p/124895#M46376</guid>
      <dc:creator>Shyam01</dc:creator>
      <dc:date>2016-11-08T09:32:26Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Login attempts with Root account from external IPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-login-attempts-with-root-account-from-external-ips/m-p/124949#M46384</link>
      <description>&lt;P&gt;For GlobalProtect:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/71/globalprotect/globalprotect-admin-guide/globalprotect-quick-configs" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/71/globalprotect/globalprotect-admin-guide/globalprotect-quick-configs&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2016 13:38:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-login-attempts-with-root-account-from-external-ips/m-p/124949#M46384</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-11-08T13:38:10Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Login attempts with Root account from external IPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-login-attempts-with-root-account-from-external-ips/m-p/125057#M46389</link>
      <description>&lt;P&gt;To add to this if you are remotely managing these devices then I would highly recommend setting a management profile that strictly limits the amount of IP addresses that can actually manage this device. That way you can not only be secure in knowing that nobody can just login to your device but they won't even see the login page or get access to the devices management if they don't have the set IP addresses.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2016 19:12:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-login-attempts-with-root-account-from-external-ips/m-p/125057#M46389</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-11-08T19:12:22Z</dc:date>
    </item>
  </channel>
</rss>

