Community discussions

MikroTik App
 
network99
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 90
Joined: Wed Nov 22, 2017 8:47 pm

if 5 times try to connect ssh, src address deny !

Tue Aug 17, 2021 6:17 pm

hello guys
good time

I want to if everyone try to connect ssh in 5 times, my router deny his/her src address !
how to detect failed and wrong password connection 5 times in 1 minute ?

have you seen
 
User avatar
rextended
Forum Guru
Forum Guru
Posts: 12442
Joined: Tue Feb 25, 2014 12:49 pm
Location: Italy
Contact:

Re: if 5 times try to connect ssh, src address deny !

Tue Aug 17, 2021 6:40 pm

You made SSH available to public?

Close SSH to public and use VPN
 
joegoldman
Forum Veteran
Forum Veteran
Posts: 775
Joined: Mon May 27, 2013 2:05 am

Re: if 5 times try to connect ssh, src address deny !

Wed Aug 18, 2021 3:34 am

Yes possible, using 'dst-limit' on the 'new' connection state in ip firewall filter or an old, long way is to create staged address-lists with short timeoutes.

Management stuff - as rextended suggested, is much better over VPN with maybe some kind of port-knock system to get in - in those rare instances VPN is not available (some carrier NAT or hotspot systems may block it)

Who is online

Users browsing this forum: Bing [Bot], GoogleOther [Bot], satboxbg, the2masters and 30 guests