GL-AX1800 (Flint) dropped SSH connections from Internet

I am seeing loads of connection attempts to SSH from the Internet

Anyone knows what this is?

Thu Dec  2 14:24:49 2021 authpriv.info dropbear[1827]: Child connection from 43.252.228.50:49536
Thu Dec  2 14:24:56 2021 authpriv.warn dropbear[1827]: Bad password attempt for 'root' from 43.252.228.50:49536
Thu Dec  2 14:24:58 2021 authpriv.info dropbear[1827]: Exit before auth (user 'root', 1 fails): Exited normally
Thu Dec  2 14:24:59 2021 authpriv.info dropbear[2583]: Child connection from 43.252.228.50:50274
Thu Dec  2 14:25:07 2021 authpriv.warn dropbear[2583]: Bad password attempt for 'root' from 43.252.228.50:50274
Thu Dec  2 14:25:09 2021 authpriv.info dropbear[2583]: Exit before auth (user 'root', 1 fails): Exited normally
Thu Dec  2 14:25:09 2021 authpriv.info dropbear[3498]: Child connection from 43.252.228.50:51058
Thu Dec  2 14:25:15 2021 authpriv.warn dropbear[3498]: Bad password attempt for 'root' from 43.252.228.50:51058
Thu Dec  2 14:25:17 2021 authpriv.info dropbear[3498]: Exit before auth (user 'root', 1 fails): Exited normally
Thu Dec  2 14:25:17 2021 authpriv.info dropbear[3933]: Child connection from 43.252.228.50:51748
Thu Dec  2 14:25:24 2021 authpriv.warn dropbear[3933]: Bad password attempt for 'root' from 43.252.228.50:51748
Thu Dec  2 14:25:27 2021 authpriv.info dropbear[3933]: Exit before auth (user 'root', 1 fails): Exited normally
Thu Dec  2 14:25:27 2021 authpriv.info dropbear[11189]: Exit before auth: Timeout before auth
Thu Dec  2 14:25:28 2021 authpriv.info dropbear[4982]: Child connection from 43.252.228.50:52506
Thu Dec  2 14:25:35 2021 authpriv.warn dropbear[4982]: Bad password attempt for 'root' from 43.252.228.50:52506
Thu Dec  2 14:25:37 2021 authpriv.info dropbear[4982]: Exit before auth (user 'root', 1 fails): Exited normally
Thu Dec  2 14:25:38 2021 authpriv.info dropbear[5699]: Child connection from 43.252.228.50:53262
Thu Dec  2 14:25:44 2021 authpriv.warn dropbear[5699]: Bad password attempt for 'root' from 43.252.228.50:53262
Thu Dec  2 14:25:46 2021 authpriv.info dropbear[5699]: Exit before auth (user 'root', 1 fails): Exited normally
Thu Dec  2 14:25:46 2021 authpriv.info dropbear[6708]: Child connection from 43.252.228.50:53898
Thu Dec  2 14:25:53 2021 authpriv.warn dropbear[6708]: Bad password attempt for 'root' from 43.252.228.50:53898
Thu Dec  2 14:25:54 2021 authpriv.info dropbear[6708]: Exit before auth (user 'root', 1 fails): Exited normally
Thu Dec  2 14:25:56 2021 authpriv.info dropbear[7720]: Child connection from 43.252.228.50:54574
Thu Dec  2 14:26:03 2021 authpriv.warn dropbear[7720]: Bad password attempt for 'root' from 43.252.228.50:54574
Thu Dec  2 14:26:05 2021 authpriv.info dropbear[7720]: Exit before auth (user 'root', 1 fails): Exited normally
Thu Dec  2 14:26:06 2021 authpriv.info dropbear[8649]: Child connection from 43.252.228.50:55406

Did you enable DDNS and SSH access?

When you enable SSH Access, someone on the Internet can try to connect to your router. In the case it shows that ssh access is failed.

I suggest that you turn off SSH Access from the WAN side.

Yes that must have been it.
I disabled DDNS and these entires stopped showing in log.

1 Like