Forum Discussion
ssh attack
i have one SSH vip that has been getting attacks from different IPs with admin, root, and some other IDs but wrong password. Is there a way to block this, Thank you for your help.
4 Replies
- VernonWells
Employee
You can block source IP addresses, but you cannot, at the BIG-IP, block by user. BIG-IP does not perform ssh offloading, and as such, cannot read the username (which is encrypted).
Is there any irule to prevent the same?
- VernonWells
Employee
Unhappily, no. Again, the problem is that ssh starts with a handshake, after which all following data are encrypted. The encrypted stream includes authentication material (including username and password). The BIG-IP cannot read the encrypted stream because it is effectively a "man-in-the-middle".
- Gabe_31218
Nimbostratus
Vernon's right, since ssh is encrypted so you can't do much about the traffic. But there are things you can do to minimize the attack surface :) You can work on blocking source IP by geographic locations. The following URL will be a good start: https://devcentral.f5.com/wiki/iRules.whereis.ashx
Cheers, Gabe
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com