cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
502
Views
0
Helpful
1
Replies

SSH attacks - how concerned should I be?

randallrathbun
Level 1
Level 1

How concerned should I be on SSH attacks on port 22 on my outside interface which currently has the implicit ACL rule to deny any traffic from the outside interface to the outside interface?

I have noticed that this attack seems to start at 4 am in the morning local time and runs until about 8 am which is the typical start of the business day, so apparently the people trying to do the brute force login attempts know the local time, although I have seen some attempts during business hours, such as 10:30 am this morning.

I have one implicit rule, are there better access rules to install and use to deny these attempts?

1 Reply 1

Panos Kampanakis
Cisco Employee
Cisco Employee

You can use the "ip ssh authentication-retries" option to lock him out after some attempts.

The default is 5, is he doing more than 5 and how often and different or same ip address?

I hope it helps.

PK

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: