forcing access to junos device

    Posted 04-19-2020 23:14


    There is a number of unauthorize attempts to the Juniper device. 

    mx>show log messages | match LOGIN_FAILED 



    There are the following KBs but these for srx, how about ex/qfx and mx?

    Any workaround or best practice?




    Posted 04-19-2020 23:21

    Hi Arix


    For the qfx/mx device you can use the following method to avoid the ssh/telnet brute force attack. Please refer to the below document



    Hope this helps

    Posted 04-20-2020 02:21


    both KBs also apply to MX and I suppose to all other JUNOS platforms.



    Posted 04-20-2020 04:08

    Thanks answers....

    When checking those juniper resources, a few questions are caming up...

    How can weird people(brute forcers) around the world know my junos devices' management ip addresses? The answer should be a ping sweep, shouldn't be?

    How can be hide/not propagate or not annnouced IP addresses that are using for only internal management purpose?

    How to verify this brute force attempts or requests are coming to which IP addresses on the Junos devices? I know there is no establishing but I need to know which destionation Ip address is being used by brute forcers?

    Posted 04-20-2020 09:12



    If your IP management using Public IP then its normal all arround the world know. So the to perevent is just using lo0 filter such as KB mention.



    Posted 04-20-2020 16:46


    I just checked my tracert to google. In the path we can see lo0 interface with its ip address. Probably lo0 is a router-id or probably it is being using for dynamic routing protocol. So if the Firewall Filter is not applied to this Lo0 interface, will my SSH attemp to this lo0 show a SSH_LOGIN_FAILED in the their message log? If the FF is applied, what might be seen?  



    Tracing route to []
    over a maximum of 30 hops:
      1     1 ms    <1 ms    <1 ms  Bilolight []
      2    17 ms    16 ms    26 ms []
      3    19 ms    19 ms    39 ms []
      4    30 ms    32 ms    37 ms []
      5    28 ms    31 ms    43 ms []
      6    28 ms    29 ms    30 ms []
      7    36 ms    30 ms    53 ms []
      8    30 ms    42 ms    30 ms
      9    30 ms    34 ms    28 ms
     10    39 ms    29 ms    29 ms []
    Trace complete.




    Other things....The Junos device mx has multiple interfaces and multiple lo(X) logical interfaces. Each traffic on the each interfaces is different as expected.

    In windows we can determine which incoming source addresses to which destination address with netstat -a etc.

    In Junos cli (including shell) what is the equivalent of windows command of netstat -ona 2 | find "x.x.x.x" | find "22" regartless what interfces might be.?



    Posted 04-22-2020 07:25

    any reply?

    Posted 04-22-2020 21:23

    Hi Arix


    When you apply the firewall filter for the lo0 interface you apply the filter on the physical interface. So it doesnt matter if there are multiple logical unit associated the filter will work for all the traffic which are attempted towards the lo0.

    If you want to find out the source and destination ip address from the brute force attack you may use the "log" option in the firewall filter along with count to determine the source of the brute force attack. However i am not sure if "log" option on loopback works on all the junos devices.


    Also when the firewall filter is applied to the lo0 you may not see the SSH_FAILED attempt as it will be dropped before it hits the cpu.

    Posted 04-23-2020 22:12

    Hi Arix,


    Hi Arix,