Skip to main content

2 replies

dbu
Staff
Staff
December 27, 2023

Hi @Anonymous_User ,
Are you facing an issue trying to implement this solution ? 
I have not done it myself but i can help you troubleshoot it. 

ebilcari
Staff
Staff
December 28, 2023

I guess that your requirement is not the same with the article you mentioned. It will differentiate between two different protocols sharing the same port. In your case you are trying to differentiate on the authentication type used for SSH. I can't think of a way for FGT to block this, the easiest way could be limiting it from the server side.

Emirjon
ebilcari
Staff
Staff
January 2, 2024

Theoretically this can be achieved using custom IPS signature. If it's possible to build a custom pattern that is seen only during the SSH session when credentials are used, than chose to drop that traffic. I don't have experience with this but this article or this guide may help.

Emirjon