I happen to check the log and there were a lot of these message
login failure from user abcde from 222.xxx.xxx by ssh
saro
123
456
Always from 222.xxx.xxx
It did not stop untill I dropped the dsl connection.
Can someone tell me what this is
It was coming from a different 222.xxx address every minute. Would that be somekind of scan for open ip?
Hi ;
from your winbox go to the menu ip → services
disable the ftp , ssh and www-ssl , then you will block all the attempts coming from ssh to your MT .
Thanks for the link , i will read it later and check if i already have it in my firewall filter rules or not
with best regards .
The second line must be the last entry in your input filter list.
Insure they are entered in that order.
xx.xx.xx.xx/24 is your wan net.
And you still get access to everything! But beware! If you don’t have a null modem cable handy, this could lock you out if not entered correctly.
NOTE: Here is the way I lock myself out of my boxes most often. If you don’t like the way the rules are working and want to delete them, REMOVE THAT SECOND LINE FIRST!! Otherwise, the only input rule is the second one, which is “everybody is locked out”. When the response from the box suddenly stops, you’ll know what I mean.
Just a quick question, is there a way to drop the CLI commands into winbox (I assume not). I am very bad at CLI as I am unable to think in text, I am very much object oriented. Which makes translating the CLI that everyone is posting into the proper action through WinBox a bit difficult.
Example: I am seeing the firewall info that shows ftp address blacklist;