12-11-2012 04:33 AM - edited 03-07-2019 10:32 AM
I have Nexus 7K installations in 2 locations. Both of them have multiple VDCs. In default VDC there are continous tacacs error message though tacacs is not configured. The requests are from various public IPs where thsi VDC is not exposed to Internet at all. What would be t he cause of it?
%AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user root from 195.2.219.2
2012 Dec 11 16:25:28 IDC-FBDTB-AMR2-CN7K-01 %AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user nagios from 67.78.206.226
- sshd[25797]
2012 Dec 11 16:25:34 IDC-FBDTB-AMR2-CN7K-01 %AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user nagios from 67.78.206.226
- sshd[25799]
2012 Dec 11 16:25:39 IDC-FBDTB-AMR2-CN7K-01 %AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user ftp1 from 67.78.206.226 -
sshd[25800]
2012 Dec 11 16:25:44 IDC-FBDTB-AMR2-CN7K-01 %AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user ftp1 from 67.78.206.226 -
sshd[25805]
2012 Dec 11 16:25:49 IDC-FBDTB-AMR2-CN7K-01 %AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user informix from 67.78.206.2
26 - sshd[25846]
2012 Dec 11 16:25:54 IDC-FBDTB-AMR2-CN7K-01 %AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user informix from 67.78.206.2
26 - sshd[25848]
2012 Dec 11 16:26:00 IDC-FBDTB-AMR2-CN7K-01 %AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user PlcmSpIp from 67.78.206.2
26 - sshd[25849]
2012 Dec 11 16:26:05 IDC-FBDTB-AMR2-CN7K-01 %AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user PlcmSpIp from 67.78.206.2
26 - sshd[25850]
2012 Dec 11 16:26:11 IDC-FBDTB-AMR2-CN7K-01 %AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user upload from 67.78.206.226
- sshd[25852]
2012 Dec 11 16:26:17 IDC-FBDTB-AMR2-CN7K-01 %AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user upload from 67.78.206.226
- sshd[25857]
2012 Dec 11 16:26:23 IDC-FBDTB-AMR2-CN7K-01 %AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user upload from 67.78.206.226
- sshd[25858]
2012 Dec 11 16:26:28 IDC-FBDTB-AMR2-CN7K-01 %AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user usuario from 67.78.206.22
6 - sshd[25863] 2012 Dec 11 16:25:28 IDC-FBDTB-AMR2-CN7K-01 %AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user nagios from 67.78.206.226
- sshd[25797]
2012 Dec 11 16:25:34 IDC-FBDTB-AMR2-CN7K-01 %AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user nagios from 67.78.206.226
- sshd[25799]
2012 Dec 11 16:25:39 IDC-FBDTB-AMR2-CN7K-01 %AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user ftp1 from 67.78.206.226 -
sshd[25800]
2012 Dec 11 16:25:44 IDC-FBDTB-AMR2-CN7K-01 %AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user ftp1 from 67.78.206.226 -
sshd[25805]
2012 Dec 11 16:25:49 IDC-FBDTB-AMR2-CN7K-01 %AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user informix from 67.78.206.2
26 - sshd[25846]
2012 Dec 11 16:25:54 IDC-FBDTB-AMR2-CN7K-01 %AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user informix from 67.78.206.2
26 - sshd[25848]
2012 Dec 11 16:26:00 IDC-FBDTB-AMR2-CN7K-01 %AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user PlcmSpIp from 67.78.206.2
26 - sshd[25849]
2012 Dec 11 16:26:05 IDC-FBDTB-AMR2-CN7K-01 %AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user PlcmSpIp from 67.78.206.2
26 - sshd[25850]
2012 Dec 11 16:26:11 IDC-FBDTB-AMR2-CN7K-01 %AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user upload from 67.78.206.226
- sshd[25852]
2012 Dec 11 16:26:17 IDC-FBDTB-AMR2-CN7K-01 %AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user upload from 67.78.206.226
- sshd[25857]
2012 Dec 11 16:26:23 IDC-FBDTB-AMR2-CN7K-01 %AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user upload from 67.78.206.226
- sshd[25858]
2012 Dec 11 16:26:28 IDC-FBDTB-AMR2-CN7K-01 %AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user usuario from 67.78.206.22
6 - sshd[25863]
12-11-2012 04:41 AM
Hi
It looks like failed connections to the SSH server on your N7k. I think these connection attemps are sourced by some kind of NMS station (or automatic scripts). Check your NMS-systems, seems like your N7k is discovered and the NMS is now trying to get some information out of your N7k's.
HTH
Marcel
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide