• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Multiple unexpected login "beeps"...

Scheduled Pinned Locked Moved General pfSense Questions
12 Posts 5 Posters 440 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • I
    IanMcLeish
    last edited by Mar 27, 2025, 7:54 PM

    Can anyone give me some advice please? I have been running a community pfsense, installed on a 4 port protectli vault for about 2 years now. I never had an issue.

    I installed the pfsense to use as a router, because the Starlink router wouldn't play nice with the 5 other routers I have, all in AP mode! to get wifi around my strange house. Very bad wifi strengths without multiple routers! All was well.

    I am not a "homelabber" as such, but I did set up an Unraid box to replace a very old Windows Home Server which was dying- can't complain, it was running for over a decade, but I didn't want to lose all, so I went with Unraid, on another Protectli box- a bad choice as all disks are attached through an external cage over usb C 3.1 I think.

    Anyhoo, I was at work today and noticed some uploading on the unraid, and I couldn't find out why. I was logged into it remotely, over tailscale, but it was doing about 20MbitPS up.

    I looked online to see if PfSense had a way of monitoring traffic by client and found a video about ntopng, which I installed and configured, I think.

    It was a bit bamboozling to me, but there was some traffic I didn't recognise. An upload to an ip address which wasn't my VPS or anything else I could think about.

    When I got home, doing some more investigating, my pfsense box beeped, which it does when someone logs in. I went looking for logs but can't really say if I found anything. As this was strange, and I DID install ntopng with the same password, I thought that must be it, so I uninstalled the package.

    Still getting unexpected pings from the pfsense.

    I disconnected the internet and changed the password to the pfsense, and I then re-enabled the internet. It may have settled down now, but there were a couple of unexpected "login" beeps even after the password change.

    Long story short, have I been hacked somehow? Is there a way to check in the logs who was logging in? Maybe it was my computer (local) reauthenticating, but not on my part, and I have never heard this happen before today.

    Any advise would be gratefully recieved.

    Thank you.
    Ian

    Community latest version 2.7.2-RELEASE (amd64)

    It just beeped again!

    S G 2 Replies Last reply Mar 27, 2025, 9:23 PM Reply Quote 0
    • S
      SteveITS Galactic Empire @IanMcLeish
      last edited by Mar 27, 2025, 9:23 PM

      @IanMcLeish The console and system log should show user logins.

      Mar 27 16:22:54 php-fpm 99362 /index.php: Successful login for user 'admin' from: ______ (Local Database)

      Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
      When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
      Upvote 👍 helpful posts!

      1 Reply Last reply Reply Quote 1
      • S
        stephenw10 Netgate Administrator
        last edited by Mar 28, 2025, 1:24 AM

        Yup, it would be logged. Both in the System log and the Authentication log.

        [2.7.2-RELEASE][admin@t70.stevew.lan]/root: grep login /var/log/auth.log 
        Feb 15 16:54:31 t70 php-fpm[98161]: /index.php: Successful login for user 'admin' from: 172.21.16.8 (Local Database)
        Mar  4 13:09:10 t70 php-fpm[2495]: /index.php: Successful login for user 'admin' from: 172.21.16.8 (Local Database)
        Mar 17 00:51:09 t70 php-fpm[32432]: /index.php: Successful login for user 'admin' from: 172.21.16.8 (Local Database)
        Mar 28 01:15:58 t70 php-fpm[18718]: /index.php: Successful login for user 'admin' from: 172.21.16.8 (Local Database)
        
        
        1 Reply Last reply Reply Quote 0
        • I
          IanMcLeish
          last edited by Mar 28, 2025, 7:58 AM

          @stephenw10 said in Multiple unexpected login "beeps"...:

          Successful login for user 'admin' from:

          Thank you both, I looked at the logs and there are so many attacks, but I don't see any unauthorised access. Don't know why it is beeping.

          Maybe it doesn't only beep on a successful login, but that was my experience until now.

          I recently had fibre installed and 2 days later a car took out all the fibre lines! So until Tuesday I was perhaps less exposed to these attacks, behind Starlink's CGNAT, but now I have a public static ip address.

          Didn't realise how many attacks a router would need to defend against!

          Thanks again, I'll keep an eye on those logs!

          J S 2 Replies Last reply Mar 28, 2025, 9:43 AM Reply Quote 0
          • J
            johnpoz LAYER 8 Global Moderator @IanMcLeish
            last edited by johnpoz Mar 28, 2025, 9:46 AM Mar 28, 2025, 9:43 AM

            @IanMcLeish said in Multiple unexpected login "beeps"...:

            Didn't realise how many attacks a router would need to defend against!

            Not sure I would call noise "attacks" yes there will lots of attempts to see if you have ports open, sure there will be brute force attempts to login to exposed ssh or ftp, etc

            But I wouldn't call your firewall dropping packets that are not allowed "attacks" - do you have ssh exposed to the public internet, or other services? All the common ports, ssh, ftp, rdp, sql, etc.. will always see lots of noise.

            So like in the last 24 hours - 96 hits to ssh (22).. None of those would actually get to attempt to login in because I don't have 22 even allowed.. But most of them wouldn't be allowed even if I had 22 open because I block most of those are IPs, I don't allow because they are known scanners (shodan, etc), not coming from US ips - or just noise producers like digital ocean - nothing good will ever talk to you from a DO ip ;)

            2025-03-28_043120.jpg

            See that last one there must be a US IP, and not in my known scanners list or DO block - so if was open he would be allowed.

            But yeah if your behind a cgnat - you wouldn't see any unsolicited inbound traffic - calling them attacks sure if you want ;)

            The internet is a noisy place. I sure wouldn't expose ssh to the public internet - vpn in if you need remote access. Or if you must use something like ssh, whitelist to known good IPs and for sure only allow public key auth.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • S
              stephenw10 Netgate Administrator @IanMcLeish
              last edited by Mar 28, 2025, 1:48 PM

              @IanMcLeish said in Multiple unexpected login "beeps"...:

              I looked at the logs and there are so many attacks

              What exactly are you seeing? Failed login attempts? If so that's bad, you should not have the firewall webgui open to the internet.

              If it's just firewall logs on WAN then, yes, that's pretty much expected if you have a public IP.

              J 1 Reply Last reply Mar 28, 2025, 2:47 PM Reply Quote 0
              • G
                Gertjan @IanMcLeish
                last edited by Gertjan Mar 28, 2025, 1:55 PM Mar 28, 2025, 1:55 PM

                @IanMcLeish said in Multiple unexpected login "beeps"...:

                Is there a way to check in the logs who was logging in?

                That's what this log is all about : Status > System Logs > Authentication > General

                GUI logins are very recognizable :

                4ff0c661-e37a-4295-a802-4087328fe7f9-image.png

                and normally, only the admin user can login from a LAN - or whatever you decide - network.
                WAN is normally impossible of course.
                Possible that a package also beeps, as its a system call or a simple shells script.

                edit : .... didn't saw the reply of everybody else 😖

                No "help me" PM's please. Use the forum, the community will thank you.
                Edit : and where are the logs ??

                1 Reply Last reply Reply Quote 1
                • J
                  johnpoz LAYER 8 Global Moderator @stephenw10
                  last edited by Mar 28, 2025, 2:47 PM

                  @stephenw10 said in Multiple unexpected login "beeps"...:

                  you should not have the firewall webgui open to the internet.

                  QFT

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  I 1 Reply Last reply Mar 29, 2025, 2:19 PM Reply Quote 1
                  • I
                    IanMcLeish @johnpoz
                    last edited by IanMcLeish Mar 29, 2025, 2:20 PM Mar 29, 2025, 2:19 PM

                    @johnpoz said in Multiple unexpected login "beeps"...:

                    @stephenw10 said in Multiple unexpected login "beeps"...:

                    you should not have the firewall webgui open to the internet.

                    QFT

                    I just made a new post about this before reading this. It is open to the internet, and I do not know for the life of why it is or how it got to be.

                    And I don't know how to set it to not be available!!

                    J 1 Reply Last reply Mar 29, 2025, 3:09 PM Reply Quote 0
                    • J
                      johnpoz LAYER 8 Global Moderator @IanMcLeish
                      last edited by johnpoz Mar 29, 2025, 7:04 PM Mar 29, 2025, 3:09 PM

                      @IanMcLeish well what are your firewall rules on your wan - the only way it would be open to the internet is if you have a rule that allows it. Remove such a rule - post up your wan rules.

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      I 1 Reply Last reply Mar 29, 2025, 4:53 PM Reply Quote 0
                      • I
                        IanMcLeish @johnpoz
                        last edited by Mar 29, 2025, 4:53 PM

                        @johnpoz said in Multiple unexpected login "beeps"...:

                        @IanMcLeish well what are your firewall rules on your lan - the only way it would be open to the internet is if you have a rule that allows it. Remove such a rule - post up your wan rules.

                        |I got it sorted out on the other post, it was all down to my stupidity, unsurprisingly.

                        All my bad. But yes, checking my firewall rules sorted out my problem, so thanks for the suggestion.

                        Ian

                        1 Reply Last reply Reply Quote 1
                        • S
                          stephenw10 Netgate Administrator
                          last edited by stephenw10 Mar 29, 2025, 5:19 PM Mar 29, 2025, 5:18 PM

                          You must have a firewall rule allowing it since all traffic inbound is blocked by default.

                          So check the WAN firewall rules. If there's nothing there check for interface groups or floating rules.

                          Post some screenshots if you're unsure.

                          Edit: Ooops hit post after like 2hrs. 🙄

                          1 Reply Last reply Reply Quote 0
                          2 out of 12
                          • First post
                            2/12
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                            This community forum collects and processes your personal information.
                            consent.not_received