<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Brute Force Attack (SSH) in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/brute-force-attack-ssh/m-p/83834#M20372</link>
    <description>&lt;P&gt;I have a blackdiamong 8806 and I am having brute force attacks (ssh), someone has an idea on how I can protect the equipment&amp;nbsp;since in the knowledge base I only found related information for EOS but not for XOS.&lt;/P&gt;&lt;P&gt;Hopefully they can help me.&lt;/P&gt;</description>
    <pubDate>Tue, 10 Nov 2020 13:08:17 GMT</pubDate>
    <dc:creator>jflores</dc:creator>
    <dc:date>2020-11-10T13:08:17Z</dc:date>
    <item>
      <title>Brute Force Attack (SSH)</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/brute-force-attack-ssh/m-p/83834#M20372</link>
      <description>&lt;P&gt;I have a blackdiamong 8806 and I am having brute force attacks (ssh), someone has an idea on how I can protect the equipment&amp;nbsp;since in the knowledge base I only found related information for EOS but not for XOS.&lt;/P&gt;&lt;P&gt;Hopefully they can help me.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2020 13:08:17 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/brute-force-attack-ssh/m-p/83834#M20372</guid>
      <dc:creator>jflores</dc:creator>
      <dc:date>2020-11-10T13:08:17Z</dc:date>
    </item>
    <item>
      <title>Re: Brute Force Attack (SSH)</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/brute-force-attack-ssh/m-p/83835#M20373</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;you can for example limit the ssh access to some ip’s like descripted here:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://gtacknowledge.extremenetworks.com/articles/How_To/Create-an-ACL-on-an-XOS-switch-for-SSH2-service-access" target="_blank" rel="nofollow noreferrer noopener"&gt;https://gtacknowledge.extremenetworks.com/articles/How_To/Create-an-ACL-on-an-XOS-switch-for-SSH2-service-access&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2020 13:50:16 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/brute-force-attack-ssh/m-p/83835#M20373</guid>
      <dc:creator>StephanH</dc:creator>
      <dc:date>2020-11-10T13:50:16Z</dc:date>
    </item>
    <item>
      <title>Re: Brute Force Attack (SSH)</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/brute-force-attack-ssh/m-p/83836#M20374</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also take in mind that if it would be just simple brute force&amp;nbsp;with a small number of requests for connection via ssh&amp;nbsp;- it’s good to have “configure ssh2 access-profile ...”.&lt;/P&gt;&lt;P&gt;But if it would be a lot of requests for connection and it can be like DDoS, it’s better to create ACL (accept ssh from specific IP and deny from all other) and map it on ingress to ports or vlans.&lt;/P&gt;&lt;P&gt;Because access policy “configure ssh2 access-profile” is proceed by CPU but&amp;nbsp;in case of ACL mapped to port (or vlan) packets don’t reach the&amp;nbsp;CPU, so in this case mgmt plane load will be reduced.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2020 14:46:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/brute-force-attack-ssh/m-p/83836#M20374</guid>
      <dc:creator>Alexandr_P</dc:creator>
      <dc:date>2020-11-10T14:46:00Z</dc:date>
    </item>
    <item>
      <title>Re: Brute Force Attack (SSH)</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/brute-force-attack-ssh/m-p/83837#M20375</link>
      <description>&lt;P&gt;Is the Switch accessible via the Internet? If not the above measures are good against the symptoms, but not against the cause.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2020 17:19:22 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/brute-force-attack-ssh/m-p/83837#M20375</guid>
      <dc:creator>Stefan_K_</dc:creator>
      <dc:date>2020-11-10T17:19:22Z</dc:date>
    </item>
  </channel>
</rss>

