SSH attacks - how concerned should I be?

Unanswered Question
Mar 2nd, 2010

How concerned should I be on SSH attacks on port 22 on my outside interface which currently has the implicit ACL rule to deny any traffic from the outside interface to the outside interface?

I have noticed that this attack seems to start at 4 am in the morning local time and runs until about 8 am which is the typical start of the business day, so apparently the people trying to do the brute force login attempts know the local time, although I have seen some attempts during business hours, such as 10:30 am this morning.

I have one implicit rule, are there better access rules to install and use to deny these attempts?

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Panos Kampanakis Tue, 03/02/2010 - 17:34

You can use the "ip ssh authentication-retries" option to lock him out after some attempts.

The default is 5, is he doing more than 5 and how often and different or same ip address?

I hope it helps.



This Discussion