Community discussions

MikroTik App
 
cavaughan
newbie
Topic Author
Posts: 45
Joined: Sun Nov 09, 2014 8:01 pm
Location: Seattle, WA, USA
Contact:

Bruteforce ssh prevention

Thu Nov 13, 2014 3:12 am

I added the firewall filters to help prevent bruteforce logins on ssh per the instruction at:

http://wiki.mikrotik.com/wiki/Bruteforc ... %26_SSH%29

I see continual attempts that trace back to China trying to ssh in, but when I go to: /ip firewall address-list and issue print command, nothing is ever there.
Is there something else I need to do?

Since posting this I also found the following suggestion and changed everything accordingly
.
http://forum.mikrotik.com/viewtopic.php ... te#p439986
 
cavaughan
newbie
Topic Author
Posts: 45
Joined: Sun Nov 09, 2014 8:01 pm
Location: Seattle, WA, USA
Contact:

Re: Bruteforce ssh prevention

Sat Nov 15, 2014 12:57 am

So, the latter in my understanding of what it should do is not working. I'm watching right now attempted ssh logins, dozens in a row from the same ip all for root. But the rules never applied. Any ideas what's going on?
 
eyegeegeewhy
just joined
Posts: 11
Joined: Thu Oct 10, 2013 1:17 am

Re: Bruteforce ssh prevention

Tue Dec 16, 2014 2:32 pm

I could never get this working either
 
jarda
Forum Guru
Forum Guru
Posts: 7756
Joined: Mon Oct 22, 2012 4:46 pm

Re: Bruteforce ssh prevention

Tue Dec 16, 2014 3:14 pm

Check the rules order and if address lists are filled.