Pace firewall and ssh attacks

Internet access discussion, including Fusion, IP Broadband, and Gigabit Fiber!
4 posts Page 1 of 1
by tatere » Sat Dec 14, 2013 10:01 pm
I have Fusion DSL service with the Pace 4111N modem. The modem's firewall is enabled. There are a couple of ports opened, forwarding to a NAS, but that's it.

I noticed, though, that I'm seeing a lot of ssh attempts on a Linux box here. I can do the usual stuff on that box to block IPs and such, but what I don't understand is how are they getting in to begin with? Shouldn't the firewall be blocking this?
by radeyes » Mon Dec 16, 2013 9:51 am
Are you sure about this? Are the incoming IP addresses of the SSH attempts external IPs or internal ones?
I would be concerned if I saw this happening. Either you have configured port forwarding for SSH, or perhaps you have your router configured in some nonstandard way (like bridge mode or DMZ mode)
by tatere » Mon Dec 16, 2013 1:20 pm
they're external IPs, i do not have anything in DMZ mode, i am not using bridge mode, and yeah i'm a little concerned too. thus the post.
by cduran » Mon Dec 23, 2013 2:57 pm
I agree that the Pace firewall should have been blocking those SSH attempts unless:
  • The linux box was set as the DMZplus enabled device.
  • The linux box was connected to a port configured as a LAN subport.
  • The port being used for the SSH attempts was set to forward to the linux box.
  • The Pace was configured in bridge mode

It doesn't look like your Pace is still running the config mentioned in the original post. Feel free to PM me if you have some time and would like to investigate further.
Chris Duran
4 posts Page 1 of 1

Who is online

In total there are 164 users online :: 2 registered, 0 hidden and 162 guests (based on users active over the past 5 minutes)
Most users ever online was 999 on Mon May 10, 2021 1:02 am

Users browsing this forum: Ahrefs [Bot], Google [Bot] and 162 guests