<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: Continuous AAA.authfail in Logs !!! Need help in ExtremeWireless (General)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-general/continuous-aaa-authfail-in-logs-need-help/m-p/33196#M1086</link>
    <description>agree with everybody else here:&lt;BR /&gt;
- enable SSH&lt;BR /&gt;
- put an ACL on BOTH telnet and SSH&lt;BR /&gt;
- put an ACL also on SNMP (otherwise some bad guy can try to do nasty things using snmp on you switch)&lt;BR /&gt;
- if you want, DISABLE public and private snmp commuinity&lt;BR /&gt;
&lt;BR /&gt;
cheers&lt;BR /&gt;
&lt;BR /&gt;
Stefano&lt;BR /&gt;</description>
    <pubDate>Wed, 05 Apr 2017 18:57:00 GMT</pubDate>
    <dc:creator>Stefano_Dall_Os</dc:creator>
    <dc:date>2017-04-05T18:57:00Z</dc:date>
    <item>
      <title>Continuous AAA.authfail in Logs !!! Need help</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/continuous-aaa-authfail-in-logs-need-help/m-p/33190#M1080</link>
      <description>I Am having a continuous logs in my switch . see some logs below for reference &lt;BR /&gt;
&lt;BR /&gt;
04/05/2017 09:00:55.66 &lt;AAA.AUTHFAIL&gt; Login failed for user shell through telnet (5.140.0.7)04/05/2017 09:00:55.34 &lt;AAA.AUTHFAIL&gt; Login failed for user enable through telnet (70.91.21.21)&lt;BR /&gt;
04/05/2017 09:00:54.12 &lt;AAA.AUTHFAIL&gt; Login failed for user enable through telnet (5.140.0.7)&lt;BR /&gt;
04/05/2017 09:00:53.66 &lt;AAA.AUTHFAIL&gt; Login failed for user supervisor through telnet (70.91.21.21)&lt;BR /&gt;
04/05/2017 09:00:53.39 &lt;AAA.AUTHFAIL&gt; Login failed for user root through telnet (5.140.0.7)&lt;BR /&gt;
04/05/2017 09:00:52.30 &lt;DM.WARNING&gt; Switch, Code 5: Air flow mismatch detected in slot 1. Ensure all fantray and psu models are of similar air flow. (X460G2-48t-10G4, P/N: 800550-00-04, S/N: 1503N-40087, Rev: 4.0)&lt;BR /&gt;
 [7mPress &lt;SPACE&gt; to continue or &lt;Q&gt; to quit: [m [60;D [K04/05/2017 09:00:51.68 &lt;AAA.AUTHFAIL&gt; Login failed for user shell through telnet (70.91.21.21)&lt;BR /&gt;
04/05/2017 09:00:51.50 &lt;AAA.AUTHFAIL&gt; Login failed for user shell through telnet (5.140.0.7)&lt;BR /&gt;
04/05/2017 09:00:50.06 &lt;AAA.AUTHFAIL&gt; Login failed for user enable through telnet (70.91.21.21)&lt;BR /&gt;
04/05/2017 09:00:49.61 &lt;AAA.AUTHFAIL&gt; Login failed for user enable through telnet (5.140.0.7)&lt;BR /&gt;
04/05/2017 09:00:48.45 &lt;AAA.AUTHFAIL&gt; Login failed for user admin through telnet (70.91.21.21)&lt;BR /&gt;
04/05/2017 09:00:47.99 &lt;AAA.AUTHFAIL&gt; Login failed for user root through telnet (5.140.0.7)&lt;BR /&gt;
04/05/2017 09:00:46.75 &lt;AAA.AUTHFAIL&gt; Login failed for user shell through telnet (70.91.21.21)&lt;BR /&gt;
04/05/2017 09:00:46.16 &lt;AAA.AUTHFAIL&gt; Login failed for user shell through telnet (5.140.0.7)&lt;BR /&gt;
04/05/2017 09:00:45.07 &lt;AAA.AUTHFAIL&gt; Login failed for user enable through telnet (70.91.21.21)&lt;BR /&gt;
04/05/2017 09:00:44.47 &lt;AAA.AUTHFAIL&gt; Login failed for user enable through telnet (5.140.0.7)&lt;BR /&gt;
04/05/2017 09:00:43.90 &lt;AAA.AUTHFAIL&gt; Login failed for user enable through telnet (78.188.179.98)&lt;BR /&gt;
04/05/2017 09:00:43.42 &lt;AAA.AUTHFAIL&gt; Login failed for user admin through telnet (70.91.21.21)&lt;BR /&gt;
04/05/2017 09:00:42.90 &lt;AAA.AUTHFAIL&gt; Login failed for user root through telnet (5.140.0.7)&lt;BR /&gt;
04/05/2017 09:00:41.39 &lt;AAA.AUTHFAIL&gt; Login failed for user shell through telnet (70.91.21.21)&lt;BR /&gt;
&lt;BR /&gt;
This is continuously repeating in the logs ... is there a way to resolve this&lt;/AAA.AUTHFAIL&gt;&lt;/AAA.AUTHFAIL&gt;&lt;/AAA.AUTHFAIL&gt;&lt;/AAA.AUTHFAIL&gt;&lt;/AAA.AUTHFAIL&gt;&lt;/AAA.AUTHFAIL&gt;&lt;/AAA.AUTHFAIL&gt;&lt;/AAA.AUTHFAIL&gt;&lt;/AAA.AUTHFAIL&gt;&lt;/AAA.AUTHFAIL&gt;&lt;/AAA.AUTHFAIL&gt;&lt;/AAA.AUTHFAIL&gt;&lt;/AAA.AUTHFAIL&gt;&lt;/AAA.AUTHFAIL&gt;&lt;/Q&gt;&lt;/SPACE&gt;&lt;/DM.WARNING&gt;&lt;/AAA.AUTHFAIL&gt;&lt;/AAA.AUTHFAIL&gt;&lt;/AAA.AUTHFAIL&gt;&lt;/AAA.AUTHFAIL&gt;&lt;/AAA.AUTHFAIL&gt;</description>
      <pubDate>Wed, 05 Apr 2017 15:50:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/continuous-aaa-authfail-in-logs-need-help/m-p/33190#M1080</guid>
      <dc:creator>Prashanth_Kumar</dc:creator>
      <dc:date>2017-04-05T15:50:00Z</dc:date>
    </item>
    <item>
      <title>RE: Continuous AAA.authfail in Logs !!! Need help</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/continuous-aaa-authfail-in-logs-need-help/m-p/33191#M1081</link>
      <description>you should make an access list with a list of allowed ip-adresses to have access through telnet &lt;BR /&gt;
OR if you do not manage your switch through telnet -- just disable that&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Wed, 05 Apr 2017 18:18:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/continuous-aaa-authfail-in-logs-need-help/m-p/33191#M1081</guid>
      <dc:creator>Nick_Yakimenko</dc:creator>
      <dc:date>2017-04-05T18:18:00Z</dc:date>
    </item>
    <item>
      <title>RE: Continuous AAA.authfail in Logs !!! Need help</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/continuous-aaa-authfail-in-logs-need-help/m-p/33192#M1082</link>
      <description>Hello Prashanth,&lt;BR /&gt;
Below article will guide you to restrict the telnet access&lt;BR /&gt;
&lt;A href="https://gtacknowledge.extremenetworks.com/articles/How_To/How-to-restrict-telnet-access" target="_blank" rel="nofollow noreferrer noopener"&gt;https://gtacknowledge.extremenetworks.com/articles/How_To/How-to-restrict-telnet-access&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 05 Apr 2017 18:25:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/continuous-aaa-authfail-in-logs-need-help/m-p/33192#M1082</guid>
      <dc:creator>Steven_Lin</dc:creator>
      <dc:date>2017-04-05T18:25:00Z</dc:date>
    </item>
    <item>
      <title>RE: Continuous AAA.authfail in Logs !!! Need help</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/continuous-aaa-authfail-in-logs-need-help/m-p/33193#M1083</link>
      <description>Looks like your switch is reachable from the Internet and all its nefarious denizens.&lt;BR /&gt;
&lt;BR /&gt;
I'd suggest what Nick said, specifically:&lt;BR /&gt;
- enable ssh&lt;BR /&gt;
- disable telnet&lt;BR /&gt;
- if possible, only enable ssh on the management port&lt;BR /&gt;
- if not, allow ssh only from specific IPs in your network&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Wed, 05 Apr 2017 18:25:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/continuous-aaa-authfail-in-logs-need-help/m-p/33193#M1083</guid>
      <dc:creator>Frank</dc:creator>
      <dc:date>2017-04-05T18:25:00Z</dc:date>
    </item>
    <item>
      <title>RE: Continuous AAA.authfail in Logs !!! Need help</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/continuous-aaa-authfail-in-logs-need-help/m-p/33194#M1084</link>
      <description>The question is whether the clients should be able to reach the switch but we can't answer that as we don't know your network.&lt;BR /&gt;
&lt;BR /&gt;
But normaly a firewall should protect the network from the outside/internet = access to the switch shouldn't be allowed.&lt;BR /&gt;
&lt;BR /&gt;
To add a ACL to the switch or disable telnet/ssh will only deny access to the switch but doens't protect the rest of the network.&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Wed, 05 Apr 2017 18:37:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/continuous-aaa-authfail-in-logs-need-help/m-p/33194#M1084</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2017-04-05T18:37:00Z</dc:date>
    </item>
    <item>
      <title>RE: Continuous AAA.authfail in Logs !!! Need help</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/continuous-aaa-authfail-in-logs-need-help/m-p/33195#M1085</link>
      <description>I think it will be a good idea to disable telnet, and use SSH. Nick Yakimenko is right about making an ACL to allow only authorized IP addresses.</description>
      <pubDate>Wed, 05 Apr 2017 18:49:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/continuous-aaa-authfail-in-logs-need-help/m-p/33195#M1085</guid>
      <dc:creator>Leviodjos</dc:creator>
      <dc:date>2017-04-05T18:49:00Z</dc:date>
    </item>
    <item>
      <title>RE: Continuous AAA.authfail in Logs !!! Need help</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/continuous-aaa-authfail-in-logs-need-help/m-p/33196#M1086</link>
      <description>agree with everybody else here:&lt;BR /&gt;
- enable SSH&lt;BR /&gt;
- put an ACL on BOTH telnet and SSH&lt;BR /&gt;
- put an ACL also on SNMP (otherwise some bad guy can try to do nasty things using snmp on you switch)&lt;BR /&gt;
- if you want, DISABLE public and private snmp commuinity&lt;BR /&gt;
&lt;BR /&gt;
cheers&lt;BR /&gt;
&lt;BR /&gt;
Stefano&lt;BR /&gt;</description>
      <pubDate>Wed, 05 Apr 2017 18:57:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/continuous-aaa-authfail-in-logs-need-help/m-p/33196#M1086</guid>
      <dc:creator>Stefano_Dall_Os</dc:creator>
      <dc:date>2017-04-05T18:57:00Z</dc:date>
    </item>
  </channel>
</rss>

