This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos XG Admin Log User '-' failed to login from 'x.x.x.x' using ssh because of wrong credentials

This question seems to come up in the forums in the past, but I am not finding a solution to my issue.

User '-' failed to login from 'x.x.x.x' using ssh because of wrong credentials

  XG Admin log file shows me that many (not all) internal Windows clients are attempting this. No outside sources (yet?). Each client is attempting this once approximately every 24 hours. Each one has different times compared to other clients and the time does not match the clients boot up time. It is only listed once in the log for each attempt: I can reproduce the log entry by using putty and entering in the IP address of the XG unit and simply quit putty without entering a name. If I press Enter through the name prompt and enter anything for password, I get two entries in the XG's log. I have the latest firmware available installed in this unit. 

  I have scanned each client for Malware, but nothing found. Any ideas how I can locate the source of this? I had a different network act similar, but those log entries stopped about a month ago after a firmware update to 18.0.3 MR-3. Coincidence probably??

  Any way to find out what is causing this?



This thread was automatically locked due to age.
Parents
  • Hi,

    please provide a screenshot of the message. The  issue sounds like your users are trying to access maybe the user portal on the XG and failing? You could also try disabling th SSH access from internal users to actually see more details.

    Ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

Reply
  • Hi,

    please provide a screenshot of the message. The  issue sounds like your users are trying to access maybe the user portal on the XG and failing? You could also try disabling th SSH access from internal users to actually see more details.

    Ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

Children
  • Hi!

      At this time, I don't believe a local user (or multiple local users) attempting to log in directly. Some of the times are when no one is in the office and no remote connections allowed. Possibly a user installed a program (on many) clients, but there is no attempt to actually log in: No user name entered nor a password because of the single line log entry with null username. I did disable access to SSH but re-enabled it because I thought it best to find out what was initiating attempts first.

      Possibly a port scanner from a security program (of Windows??) is simply poking at ports??

      Attachment if from three separate clients. Still wondering.