- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
logs in system event in FortiGate firewall about Admin login failed
Getting logs in system event in FortiGate about "Admin login failed" and showing ip of the (Server connected to the internal network) as the source ip what to do? Is disabling SSH will work for it. or SNMP will work. Please suggest what solution we can do?
Solved! Go to Solution.
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
source - 192.168.1.5 is the source that is trying to loging to Fortigate. Please check why this source is logging and also all the login failed. so may be some script or tools using wrong password.
Also on YouTube---
Please do Subscribe
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This means that some program or human is trying to login to firewall from that particular server.
1> Check which program or person trying login ?
2> Verify if he is using correct credentials ?
3> If you don't want to login to the firewall from that server, Add trusted host configuration under the admin users.
For more details about trusted host and configuring security for admin users, visit the below link.
Also on YouTube---
Please do Subscribe
Created on ‎09-03-2024 11:23 PM Edited on ‎09-03-2024 11:24 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi rosatechnocrat,
Its showing only Server ip as source IP unable to capture any user IP logs
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
source - 192.168.1.5 is the source that is trying to loging to Fortigate. Please check why this source is logging and also all the login failed. so may be some script or tools using wrong password.
Also on YouTube---
Please do Subscribe
