Question
Unauthorized SSH Login Failed
The night following an upgraded to MR7 Patch1, I have several login attempts that are not me. I am the only one who should have access to this equipment. I am just curious what one should do in this situation? I could block the IPs but I have a feeling they would be different each time a login is attempted again. Fortigate-60 3.00-b0730 Valid and current AV & IPS Defs Below is the log: 8 2008-10-28 01:09:58 alert ssh(117.28.224.71) login Administrator NOUSER login failed from ssh(117.28.224.71) because of invalid user name 9 2008-10-28 01:09:58 alert ssh(117.28.224.71) login Administrator root login failed from ssh(117.28.224.71) because of invalid user name 10 2008-10-28 01:09:56 alert ssh(117.28.224.71) login Administrator NOUSER login failed from ssh(117.28.224.71) because of invalid user name 11 2008-10-28 01:09:56 alert ssh(117.28.224.71) login Administrator root login failed from ssh(117.28.224.71) because of invalid user name 12 2008-10-28 00:31:09 notice Fortigate scheduled update virdb(9.00680) idsdb(2.00560) aven(3.00003) idsen(1.00096) from 208.91.114.72:443 13 2008-10-27 23:47:38 alert ssh(202.67.15.18) login Administrator NOUSER login failed from ssh(202.67.15.18) because of invalid user name 14 2008-10-27 23:47:38 alert ssh(202.67.15.18) login Administrator root login failed from ssh(202.67.15.18) because of invalid user name 15 2008-10-27 23:47:35 alert ssh(202.67.15.18) login Administrator NOUSER login failed from ssh(202.67.15.18) because of invalid user name 16 2008-10-27 23:47:35 alert ssh(202.67.15.18) login Administrator root login failed from ssh(202.67.15.18) because of invalid user name Any suggestions?
