Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Blocked SSH Brute Force Attack -> Release

Hello,

the XG Firewall detected an SSH Brute Force Attack from Client to Server (seen in control center). Since that all traffic from the client to the server is blocked, also ICMP. The attack is caused by a script, that is now disabled. When the Client IP is changed in the same network, the communication works. Turning back the IP, the communication does not work.

How to find out, that the communication is blocked? I can not find any entry in Logviewer?

How to release the block from this client to that server. I want to allow the connection?

Is it possible to make an exception for some Clients for this security feature?

 

Thanks. Chris



This thread was automatically locked due to age.
Parents
  • Chris,

    can you share a screenshot of the CC?

    I guess it is the IPS that is blocking the packets. Did you check the IPS logs?

    Thanks

  • Hello Luk,

    as I wanted to post the screenshots, the message with the SSH Brute Force Attack was no more there in CC. IPS logs I have already checked. No entry.

    Because I am still testing the firewall, I have reconfigured the network configuration. I have run the script again (it is a rsync backup based on ssh). Nothing is blocked. Perhaps I have made a mistake...

    Thanks. I will post again, if I notice the problem again.

Reply
  • Hello Luk,

    as I wanted to post the screenshots, the message with the SSH Brute Force Attack was no more there in CC. IPS logs I have already checked. No entry.

    Because I am still testing the firewall, I have reconfigured the network configuration. I have run the script again (it is a rsync backup based on ssh). Nothing is blocked. Perhaps I have made a mistake...

    Thanks. I will post again, if I notice the problem again.

Children
No Data