Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    ntopng sshguard

    Scheduled Pinned Locked Moved Traffic Monitoring
    6 Posts 2 Posters 1.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      calvinchu
      last edited by

      I'm running into the situation where ntopng is triggering sshguard on pfsense causing it to ban it's own wan address. This can be resolved by relinquishing and renewing the ip address but a few minutes later sshguard moves to ban the next address. I'm interested in retaining the active device discovery in ntopng, which I think is what's causing this, but I'm uncertain how to configure things so I don't get an allergic reaction out of sshguard. Any suggestions?

      Thank you.

      johnpozJ 1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @calvinchu
        last edited by

        @calvinchu Your talking about pfsense locking out the IP.. You can add IPs to the bypass list so won't lock out on traffic from those IPs

        https://docs.netgate.com/pfsense/en/latest/config/advanced-admin.html#login-protection

        For example, it may be necessary to add entries for network monitoring systems which probe the SSH port but do not login. Otherwise such systems may be flagged as attackers.

        passlist.jpg

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        C 1 Reply Last reply Reply Quote 0
        • C
          calvinchu @johnpoz
          last edited by

          @johnpoz If I add the WAN address to the whitelist to prevent pfsense from blocking the wan address when the scanning is coming from pfsense, this suggests that this would cause sshguard to let through all attacks from the WAN and never block legitimate attacks. Is that right?

          Thanks.

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @calvinchu
            last edited by johnpoz

            @calvinchu said in ntopng sshguard:

            block legitimate attacks. Is that right?

            huh? How would a legit attack be coming from your own IP?

            Not sure why you would be having ntop using your wan interface anyway.. So your using discovery and checking all IPs on your wan network?

            Ntop should really only have lan side interfaces selected.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            C 1 Reply Last reply Reply Quote 0
            • C
              calvinchu @johnpoz
              last edited by

              @johnpoz Aha! I think that solves the problem. All interfaces were selected in the ntopng configuration. I excluded the wan interface and I think all is good.

              johnpozJ 1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator @calvinchu
                last edited by

                @calvinchu hmmm its been a while since I installed and setup ntop, and I only ever turn it on if actually looking for specific data. But I "believe" it defaults to no interfaces selected.. Prob not a good idea if it defaults to "all" interfaces being checked.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                1 Reply Last reply Reply Quote 0
                • johnpozJ johnpoz referenced this topic on
                • johnpozJ johnpoz referenced this topic on
                • johnpozJ johnpoz referenced this topic on
                • johnpozJ johnpoz referenced this topic on
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.