What's new

Remote ssh attempts even though ssh is “LAN only”

The simplest solution would surely be to stop dropbear listening on all interfaces?
Not really. Yes that would stop the dropbear case, but dropbear is already pretty secure. What it wouldn't stop is all the other services that are also listening on all interfaces. Some of those have little or no security at all.

So the real solution IMO is to find out why the firewall rules are disappearing or being corrupted after a WAN outage and fix it.
 
Last edited:
Not really. Yes that would stop the dropbear case, but dropbear is already pretty secure.
The thread was specifically about "ssh attempts" - so dropbear.
...
So the real solution IMO is to find out why the firewall rules are disappearing or being corrupted after a WAN outage and fix it.
Fair enough.
FWIW, I did see these had occurred (i.e. in the log) shortly before my router stopped accepting valid incoming calls.
This happened twice.
Both while I was away in Australia, and both fixed by getting my wife to reboot the router.

I thought I'd saved the syslogs somewhere, but currently can't find them.
 

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!

Members online

Back
Top