The night following an upgraded to MR7 Patch1, I have several login attempts that are not me.  I am the only one who should have access to this equipment.  I am just curious what one should do in this situation?  I could block the IPs but I have a feeling they would be different each time a login is attempted again.
 
 Fortigate-60 3.00-b0730
 Valid and current AV & IPS Defs
 
 Below is the log:
 
 8 2008-10-28 01:09:58 alert ssh(117.28.224.71) login Administrator NOUSER login failed from ssh(117.28.224.71) because of invalid user name 
 9 2008-10-28 01:09:58 alert ssh(117.28.224.71) login Administrator root login failed from ssh(117.28.224.71) because of invalid user name 
 10 2008-10-28 01:09:56 alert ssh(117.28.224.71) login Administrator NOUSER login failed from ssh(117.28.224.71) because of invalid user name 
 11 2008-10-28 01:09:56 alert ssh(117.28.224.71) login Administrator root login failed from ssh(117.28.224.71) because of invalid user name 
 12 2008-10-28 00:31:09 notice     Fortigate scheduled update virdb(9.00680) idsdb(2.00560) aven(3.00003) idsen(1.00096) from 208.91.114.72:443 
 13 2008-10-27 23:47:38 alert ssh(202.67.15.18) login Administrator NOUSER login failed from ssh(202.67.15.18) because of invalid user name 
 14 2008-10-27 23:47:38 alert ssh(202.67.15.18) login Administrator root login failed from ssh(202.67.15.18) because of invalid user name 
 15 2008-10-27 23:47:35 alert ssh(202.67.15.18) login Administrator NOUSER login failed from ssh(202.67.15.18) because of invalid user name 
 16 2008-10-27 23:47:35 alert ssh(202.67.15.18) login Administrator root login failed from ssh(202.67.15.18) because of invalid user name 
 
 Any suggestions?