RUGGEDCOM ROX II
User Guide
Chapter 5
Setup and Configuration
Enabling/Disabling Brute Force Attack Protection
247
• Use a firewall to limit access to SNMP
• Do not use SNMPv1
NOTE
Failed logins must happen within 10 minutes of each other to be considered malicious behavior.
Once the time has expired, the host will be allowed to access the device again. If the malicious behavior
continues from the same IP address (e.g. another 15 failed login attempts), then the IP address will be blocked
again, but the time blocked will increase by a factor of 1.5. This will continue as long as the host repeats the
same behavior.
IMPORTANT!
Enabling, disabling or making a configuration change to the firewall will reset – but not disable – the
BFA protection mechanism. Any hosts that were previously blocked will be allowed to log in again. If
multiple hosts are actively attacking at the time, this could result in reduced system performance.
When BFA protection is started, the following Syslog entry is displayed:
Jun 5 09:36:34 ruggedcom firewallmgr[3644]: Enabling Brute Force Attack Protection
When a host fails to login, an entry is logged in auth.log. For example:
Jun 5 10:12:52 ruggedcom confd[3386]: audit user: admin/0 Provided bad password
Jun 5 10:12:52 ruggedcom rmfmgr[3512]: login failed, reason='Bad password', user ipaddr='172.11.150.1'
Jun 5 10:12:52 ruggedcom confd[3386]: audit user: admin/0 Failed to login over ssh: Bad password
Auth.log also details which IP addresses are currently being blocked:
Jun 5 14:43:04 ruggedrouter sshguard[24720]: Blocking 172.59.9.1:4 for >630secs: 60 danger in 5 attacks
over 70 seconds (all: 60d in 1 abuses over 70s).
NOTE
For information about how to view auth.log, refer to
.
To enable/disable the BFA protection mechanism, do the following:
1. Change the mode to
Edit Private
or
Edit Exclusive
.
2. Navigate to
security
. The
Brute Force Attack Protection
form appears.
1
Figure 255: Brute Force Attack Protection Form
1.
Enable Check Box
3. Select the check box to enable the BFA protection mechanism, or clear it to disable the mechanism.
Содержание RUGGEDCOM RX1510
Страница 32: ...RUGGEDCOM ROX II User Guide Preface Customer Support xxxii ...
Страница 44: ...RUGGEDCOM ROX II User Guide Chapter 1 Introduction User Permissions 12 ...
Страница 62: ...RUGGEDCOM ROX II User Guide Chapter 2 Using ROX II Using the Command Line Interface 30 ...
Страница 268: ...RUGGEDCOM ROX II User Guide Chapter 4 System Administration Deleting a Scheduled Job 236 ...
Страница 852: ...RUGGEDCOM ROX II User Guide Chapter 5 Setup and Configuration Enabling Disabling an LDP Interface 820 ...