Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How can I stop so many Failed SSH Logins?

I haven't even had my SG115 on my network with an Internet connection for 24 hours yet, and I'm seeing tons of "Failed SSH Login" notifications and they are coming from IP addresses all over the world!  I have SSH disabled.  I know it's these weasel hackers trying to get in.  How can I block them from even trying SSH?  Just block them in their tracks even before they try any monkey business on my router.  Can I permanently ban IP addresses?  How about by country?  I do this for websites I maintain - just auto-block anyone coming from certain countries.  Is this possible in this device?  I want notifications about anything, but really?  I've gotten almost 300 so far and my router has barely been turned on.



This thread was automatically locked due to age.
Parents
  • Hey Steve,

    if SSH is disabled, you should not receive email notification about failed logins.

    Your UTM will not respond to those packets on port 22.

    Country Blocking is accessable through Network Protection -> Firewall....

     

    Kind regards

    Tobi

Reply
  • Hey Steve,

    if SSH is disabled, you should not receive email notification about failed logins.

    Your UTM will not respond to those packets on port 22.

    Country Blocking is accessable through Network Protection -> Firewall....

     

    Kind regards

    Tobi

Children
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?