Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SSHd and SSHGuard logs in pfSense

    Scheduled Pinned Locked Moved General pfSense Questions
    sshdsshguard
    10 Posts 2 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • U
      unififcf
      last edited by unififcf

      hello,

      I have recently seen the following logs in our pfSense logs (System/General) Not sure if the screenshot is OK and normal or if there is something going on. I looked at the system and I don't see anything right yet unusual?

      Screenshot_20220629-131908_Firefox.jpg

      johnpozJ 1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @unififcf
        last edited by

        @unififcf do you have something that monitors or discovers, something looking on your network for stuff listening on ssh?

        That is one of your local IPs 192.168.120.20

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

        U 1 Reply Last reply Reply Quote 0
        • U
          unififcf @johnpoz
          last edited by

          @johnpoz

          On that PC, we did have a monitor but not looking specifically for SSH connections. just packet captures in general. we also had putty on there, but that's really it.

          I removed everything I saw on the local machine, but didn't see anything else related to SSH.

          Since I am not well versed here, I just don't know what to say.

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @unififcf
            last edited by

            @unififcf Well clearly something from that IP is hitting pfsense IP.. Maybe look on that box for what is making the connection..

            netstat can be used both on windows or linux for finding the PID of what is making a connection. To track down what is causing the connection attempts

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

            U 2 Replies Last reply Reply Quote 1
            • U
              unififcf @johnpoz
              last edited by

              @johnpoz

              OK...let me use that...didn't think about using netstat. i'll give that a shot.

              thanks!

              1 Reply Last reply Reply Quote 0
              • U
                unififcf @johnpoz
                last edited by

                @johnpoz

                Would rumble.run app be doing that? I do use that for network discovery.

                johnpozJ 1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator @unififcf
                  last edited by

                  @unififcf said in SSHd and SSHGuard logs in pfSense:

                  I do use that for network discovery.

                  hehe - yeah quite possible, I don't know that app specific, but if its used for network discovery its quite likely its talking to IPs on common services, etc. to see if they listen, etc.

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                  U 1 Reply Last reply Reply Quote 1
                  • U
                    unififcf @johnpoz
                    last edited by

                    @johnpoz

                    you have been such a huge help!
                    that pointed me in the right direction...

                    just chatted with rumble team and this is the response:

                    "We do probe ssh and send a username, but we do NOT sent a password (so it’s not a full login attempt)."

                    johnpozJ 1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator @unififcf
                      last edited by

                      @unififcf can you adjust it so it doesn't check pfsense for ssh?

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                      U 1 Reply Last reply Reply Quote 1
                      • U
                        unififcf @johnpoz
                        last edited by

                        @johnpoz
                        Yes sir they said that I can disable that

                        It is a huge burden off my shoulders

                        1 Reply Last reply Reply Quote 1
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.