This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How to block SSH scans with IPS

I have created a new rule set and added everything that matches SSH but still I do see people trying my SSH server:

Nov 12 10:18:34 bananapi root: DENY sshd connection from 193.33.8.98 (PL)
Nov 12 10:18:34 bananapi sshd[32506]: aclexec returned 1
Nov 12 10:18:34 bananapi sshd[32506]: refused connect from 193.33.8.98 (193.33.8.98)

I have the following rule set for the SSH port forward firewall rule:



How can I block SSH scan attempts or why are scan attempts continuing through the IPS rules?



This thread was automatically locked due to age.
Parents Reply
  • The Point is: XG gives you the possibility to write your own IPS Rules. So it depends now: Are you an business customer, try to build them at your own or get in touch with your sophos partner to get help to build the correct rule. 

    Or you are a home user, so feel free to build it on your own needs.

    This anti guessing feature is not implemented but can be covered by the IPS. This is my point. 

Children
No Data