Reset-Both for client/sftp server

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Reset-Both for client/sftp server

L1 Bithead

I have been noticing lots of traffic between an internal client to one of our Sftp server where the log states

SSH User Authentication Brute Force on Port 22  - Action Reset-Both.  We have checked the client and has the correct credentials for the destination.  What else should I check?  The logs on the sftp server do not indicate any errors.

3 REPLIES 3

Cyber Elite
Cyber Elite

Maybe you are transferring small files and client logs into SFTP server every time to transfer file.

By default SSH User Authentication Brute Force matches if there are more than 20 login events during 60 second period.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Your explanation sounds reasonable.  How should we address this so we don't see the traffic?

Cyber Elite
Cyber Elite

@RiveraMarco,

Whatever vulnerability profile is assigned to the security policy matching that traffic can be updated with an exception if you feel like that's the right course of action. Ideally you would build out a specific entry for that traffic and assign it it's own profile if you proceed with that exception.

  • 814 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!