- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-30-2017 05:11 AM
Hi guys,
I've noticed in my System logs that there are SSH2 brute force attempts against our firewall.
Unfortunately nothing is listed in the Traffic or Threat logs under the Monitor tab to indicate from which zone the traffic is originating from.
Why would this be the case and how can I enable logging for this in the Traffic\Threat logs to determine from which zones the traffic is originating from?
12-18-2017 04:59 AM
If there is an IP, that should probably give you an indication where the connection is coming from, but if there's nothing in your traffic logs they may be hitting a management profile on a dataplane interface (rather than the management interface):
11-30-2017 05:48 AM
Hi @TheRedBar0n
isn't there a 'from: <IP>' included in the log?
a good start would be to check incoming ssh sessions from the internet (as this is usually the most likely source)
if these are hitting your management, i would recommend removing access to your management interface from outside or at least configuring some security policy to only allow trusted sources to connect
12-18-2017 04:39 AM
Hi Reaper,
Yes there are IP's included in the System logs. I have checked my traffic logs, and the only SSH sessions are those internally outbound that we have explicitly allowed. We have recently further hardended all our public IP's, so no SSH sessions should be hitting my firewall.
How am I able to determine whether the SSH logon attempts is hitting my management IP?
12-18-2017 04:59 AM
If there is an IP, that should probably give you an indication where the connection is coming from, but if there's nothing in your traffic logs they may be hitting a management profile on a dataplane interface (rather than the management interface):
12-18-2017 05:18 AM
Thanks Reaper,
I see we previously configured 3 different management profiles.
Am I correct in saying that if there is no IPs listed in the Permitted IP Addresses, this will allow the selected services from any source IP?
12-18-2017 05:53 AM
12-19-2017 12:49 AM
Thank you Reaper, I have adjusted our management profiles and will be monitoring the system logs over the next few days. Appreciate the assistance!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!