Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Too many failed logins from several IP address for facility ssh

Our client detects multiple fail login message attempts from multiple IPs.
If by setting up that SSH only accessible from the internal network can solve this issue, can advise on how to perform it, and is any downside for this configuration?.


Firewall UTM SG330 

Firmware 9.508-10



This thread was automatically locked due to age.
Parents
  • I generally set another Port for SSH access.

    An addition to access limitations as correctly remommended otherwise, this avoids thousands of attacks done by script kiddies all over the world. Only a small security  effect but a big relief for the sshd logfile.

Reply
  • I generally set another Port for SSH access.

    An addition to access limitations as correctly remommended otherwise, this avoids thousands of attacks done by script kiddies all over the world. Only a small security  effect but a big relief for the sshd logfile.

Children
No Data