Score:0

Root login attempt ssh:notty – behind ClearOS Firewall

ba flag

I had literally 5 non terminal login attempts to root,

Authentication failure for root via sshd from 59.47.112.161 ssh:notty

(China) before Fail2ban did it's job and blocked the IP. This was on the Firewall itself and SSH is only exposed to the LAN subnets.

I am aware that this is common if the SSH server is exposed to the internet but SSH access is supposed to only be available to the company internal network, I VPN into the network if I need to do anything via SSH remotely. I also don't have thousands of log entries for failed root login attempts so it doesn't indicate that I have a config error but you never know. I’ve checked and double checked and can’t find any rules that are inadvertently allowing access to 22. Any suggestions of where all to look would be welcome. If I try log into SSH remotely the connections times out and doesn’t trigger any log entries or warnings.

This was the default config on the firewall setup which I have been running since ClearOS was still called Clarkconnect, this is the first time this has happened. I am not sure if completely disabling root will break the web config gui but I have disabled root SSH login and setup a sudo user.

Can anyone possibly shed some light on how/why this would happen so I can prevent it happing again?

djdomi avatar
za flag
nat and port forwarding is possible. but since you make a secret about your network we can only assume things
Jakes avatar
ba flag
Thanks for the response. What info would you like, my port forwarding and NAT rules?
djdomi avatar
za flag
Questions seeking installation, configuration or diagnostic help must include the desired end state, the specific problem or error, sufficient information about the configuration and environment to reproduce it, and attempted solutions. Questions without a clear problem statement are not useful to other readers and are unlikely to get good answers.
Jakes avatar
ba flag
Apologies for the late response, I have been ill. I better understand question requirements and if the incident repeats itself I will gather a lot more log and config info and ask a new question with more detail. Thank you for your time.
djdomi avatar
za flag
rather than reposting edit the question if you don't like that then it's up to you too to delete it if it's your decision
Jakes avatar
ba flag
Thank you, I will edit if necessary.
I sit in a Tesla and translated this thread with Ai:

mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.