Question about a security log entry

tesagig
tesagig Posts: 56  Ally Member
First Comment Friend Collector Third Anniversary
What is going on here?
btw, I have a GEO fencing rule WAN to Zywall for Asia.
But doesn't seem that rule triggered.


39
    
2022-10-17 13:27:01
    
alert
    
User
    
Failed login attempt to Device from ssh (incorrect password or inexistent username) [count=4]
    
[my public IP]
    
 
    
Account: root
40
    
2022-10-17 13:27:01
    
alert
    
User
    
Fail login attempt to Device from ssh (login on a lockout address) [count=4]

[my public IP]
    
 
    
Account: root

All Replies

  • Zyxel_Jeff
    Zyxel_Jeff Posts: 1,230  Zyxel Employee
    100 Answers 500 Comments Friend Collector Fourth Anniversary

    To avoid some suspicious or malicious access to your device, you can configure the Geo IP block feature and the more rigorous access way on your device, please refer to the below links:
    How to Use GeoIP Feature



    Share your feedback through our survey, make your voice heard, and win a WiFi 7 AP! https://bit.ly/2024_Survey_Community

  • tesagig
    tesagig Posts: 56  Ally Member
    First Comment Friend Collector Third Anniversary
    I do have two security policies:
    1.) any to Zywall
    2.) any to any(excluding zywall)

    both deny with a IP4 source group that includes "Asia"
    no log

    SO, I wonder why I still saw the log entry?
  • Zyxel_Jeff
    Zyxel_Jeff Posts: 1,230  Zyxel Employee
    100 Answers 500 Comments Friend Collector Fourth Anniversary
    Hi @tesagig

    Not sure if your security policy of "any to Zywall" for Geo IP blocking is the lower priority, you could move it to the higher priority as below example: 


    Share your feedback through our survey, make your voice heard, and win a WiFi 7 AP! https://bit.ly/2024_Survey_Community

  • tesagig
    tesagig Posts: 56  Ally Member
    First Comment Friend Collector Third Anniversary
    I have the GEO policies already at prio 1 and 2 (on top)
  • mMontana
    mMontana Posts: 1,389  Guru Member
    50 Answers 1000 Comments Friend Collector Fifth Anniversary
    "Block this among everything" usually work worse than "allow only this among everything", by a security standpoint.
  • Zyxel_Jeff
    Zyxel_Jeff Posts: 1,230  Zyxel Employee
    100 Answers 500 Comments Friend Collector Fourth Anniversary
    edited October 2022
    tesagig said:
    I have the GEO policies already at prio 1 and 2 (on top)
    Hi @tesagig
    You can enable "log alert" on the Geo IP blocking security policy and check Monito>Log to see if this security policy is working for you. If there are blocked messages means this security policy is working and you are protected by this policy.


    Share your feedback through our survey, make your voice heard, and win a WiFi 7 AP! https://bit.ly/2024_Survey_Community

Security Highlight