Erik66
Verified User
Hello, I have a mixed issue here. I have a DA 1.6.server with ssh on port 1xxxx set in csf.conf and CSF set to listen only on a number of ports < 10000 with port 1xxxx added as addiotnional portnumer to listen on. Also, root login has been disabled in sshd_config with 'PermitRootLogin no' and user root is not listed with AllowUsers. I thought I'd made not possible to login using SSH on ports > 1xxxx and with user root in general.
Yet, I do get thousands of listings daily in BFM with similar info:
"Jan 9 15:52:54 s03 sshd[9501]: Failed password for invalid user root from xxx.xxx.xxx.xxx port 54336 ssh2"
where the IP address is all over the place an d not in my allowed ip's list.
I don't get it. I should not see those alerts at all as I have set CSF to block anythin on ports > 10000, SSHD is set to listen on ip 1xxxx only. What causes SSHD to listen to seemingly random port numbers and why are these not blocked by CSF / iptables ?
Many thanks in advance for suggestions.
Erik
Yet, I do get thousands of listings daily in BFM with similar info:
"Jan 9 15:52:54 s03 sshd[9501]: Failed password for invalid user root from xxx.xxx.xxx.xxx port 54336 ssh2"
where the IP address is all over the place an d not in my allowed ip's list.
I don't get it. I should not see those alerts at all as I have set CSF to block anythin on ports > 10000, SSHD is set to listen on ip 1xxxx only. What causes SSHD to listen to seemingly random port numbers and why are these not blocked by CSF / iptables ?
Many thanks in advance for suggestions.
Erik