08-18-2020 06:50 AM
We have been receiving some AAA failure login attempts from external IPs. Both SSH and HTTPS to the outside interface is restricted to an external IP owned by myself so I cant work out how this could be the case. ASA version is 9.10
08-18-2020 06:57 AM
You getting request on outside interface (they gained access) or denied ?
is yout ASA Listening https and ssh port on outside interface ?
can you post the configuraiton to understand better
08-18-2020 07:00 AM
All I see in logs is AAA authentication failure against the LOCAL database. The HTTP and SSH management sessions are the only services configured to use LOCAL. SSH and HTTP is enabled on outside interface but locked down to certain IPs
08-18-2020 08:58 AM
Do you see the IP address coming from unknown ? if the ACL in place for spcific IP only allow, rest should rejected by default.
can you post some example logs please for us to understand.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide