- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-29-2023 06:12 AM
I have been noticing lots of traffic between an internal client to one of our Sftp server where the log states
SSH User Authentication Brute Force on Port 22 - Action Reset-Both. We have checked the client and has the correct credentials for the destination. What else should I check? The logs on the sftp server do not indicate any errors.
09-29-2023 06:26 AM
Maybe you are transferring small files and client logs into SFTP server every time to transfer file.
By default SSH User Authentication Brute Force matches if there are more than 20 login events during 60 second period.
09-29-2023 07:03 AM
Your explanation sounds reasonable. How should we address this so we don't see the traffic?
10-02-2023 07:49 AM
Whatever vulnerability profile is assigned to the security policy matching that traffic can be updated with an exception if you feel like that's the right course of action. Ideally you would build out a specific entry for that traffic and assign it it's own profile if you proceed with that exception.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!