Community discussions

MikroTik App
 
joan
just joined
Topic Author
Posts: 1
Joined: Tue Oct 04, 2016 10:37 am

Log messages: ssh auth timeout

Tue Oct 04, 2016 10:57 am

Hello!

It seems my mikrotik router is under a brute force attack. When I take a look to the /log I see several lines like the following: (a lot of them actually, one every 30 seconds)

"Oct/04/2016 09:35:57 memory ssh, info auth timeout"

Yesterday I configured the recommendation of Mikrotik regarding "Bruteforce login prevention" (see wiki http://wiki.mikrotik.com/wiki/Bruteforc ... prevention).

But as I understand, SSH connections are not being established because the authorisation failure, so the filtering does not apply, no IP is added to the black-list and auth timeout messages keep appearing in the log.

My question is: how do I prevent this connection attempts? It is really annoying...

I changed my ssh port, but it is a matter of time "they" will find the new one and will continue the attack.

Hope someone can give me a clue, I think this would be really interesting for anyone with a network element under a public IP.

THANKS
 
bkr9662
just joined
Posts: 1
Joined: Mon Dec 11, 2017 2:00 am

Re: Log messages: ssh auth timeout

Sat Jan 06, 2018 10:40 pm

no answer? i see the same on my log, but just one of my rb3011...
 
User avatar
pukkita
Trainer
Trainer
Posts: 3051
Joined: Wed Dec 04, 2013 11:09 am
Location: Spain

Re: Log messages: ssh auth timeout

Sun Jan 07, 2018 12:53 pm

The real question is no sane admin will leave unrestricted access to a router from the Internet.

Best practice: prevent access completely to it from the internet, set up VPN access and allow only that.

If your router IP is not fixed, use IP > Cloud.

Who is online

Users browsing this forum: 4l4R1, hazem, HeinoHomm, nbotov and 213 guests