Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Unauthorized SSH Login Failed

The night following an upgraded to MR7 Patch1, I have several login attempts that are not me. I am the only one who should have access to this equipment. I am just curious what one should do in this situation? I could block the IPs but I have a feeling they would be different each time a login is attempted again. Fortigate-60 3.00-b0730 Valid and current AV & IPS Defs Below is the log: 8 2008-10-28 01:09:58 alert ssh(117.28.224.71) login Administrator NOUSER login failed from ssh(117.28.224.71) because of invalid user name 9 2008-10-28 01:09:58 alert ssh(117.28.224.71) login Administrator root login failed from ssh(117.28.224.71) because of invalid user name 10 2008-10-28 01:09:56 alert ssh(117.28.224.71) login Administrator NOUSER login failed from ssh(117.28.224.71) because of invalid user name 11 2008-10-28 01:09:56 alert ssh(117.28.224.71) login Administrator root login failed from ssh(117.28.224.71) because of invalid user name 12 2008-10-28 00:31:09 notice Fortigate scheduled update virdb(9.00680) idsdb(2.00560) aven(3.00003) idsen(1.00096) from 208.91.114.72:443 13 2008-10-27 23:47:38 alert ssh(202.67.15.18) login Administrator NOUSER login failed from ssh(202.67.15.18) because of invalid user name 14 2008-10-27 23:47:38 alert ssh(202.67.15.18) login Administrator root login failed from ssh(202.67.15.18) because of invalid user name 15 2008-10-27 23:47:35 alert ssh(202.67.15.18) login Administrator NOUSER login failed from ssh(202.67.15.18) because of invalid user name 16 2008-10-27 23:47:35 alert ssh(202.67.15.18) login Administrator root login failed from ssh(202.67.15.18) because of invalid user name Any suggestions?
5 REPLIES 5
rwpatterson
Valued Contributor III

I get them on my FGT as well as my FTP server. Probably bots probing to gain access. I wouldn' t worry about them unless they are consuming most of your bandwidth. Just make sure you don' t have ' standard' or easily guessable account names and passwords. I avoid ' administrator' , ' admin' and the like whenever possible...

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

I did get a few other attempts the next day but not any more after that. My usernames are not easily guessable and have strong passwords so I will feel safe in that at least. What does the " NOUSER" and " root" mean anyway, where they trying to login with " administrator" as the username or is there some special root login that does not show in the UI?
Not applicable

My fgt-60 has this error these days. Does someone attempt to access ? How to strengthen my unit security?
p768
New Contributor

configure your admin users with Trusted Hosts
romanr
Valued Contributor

I would also suggest to use the trusted host feature! SSH brute-force attacks can consume a real noticeable amount of cpu time of the Fortinet unit!!! cheers.roman
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors