Question
February 13, 2008 at 01:32 PM
lstone

LAN side firewall password attack

by lstone . Updated 18 years, 6 months ago

My Symantec 300 is logging the fact that access is denied to the admin console because of wrong username or password. It lists the source IP and its always a valid private address on my LAN! So far I’ve seen 4 different addresses listed. This all started about 2 weeks ago. WAN side admin is disabled. Remote desktop requires VPN to my RRAS server and its not logging any VPN connections at these times. Also the repetition of attempts is several per second so it must be program generated.

Any ideas?

This discussion is locked

All Comments