2.44. SSHD

These log messages refer to the SSHD category.

2.44.1. [ID: 370] Administrative user logged in

Log Categories
SSHD
Log Message
Administrative user logged in.
Default Log Severity
Notice
Parameters
user, method, accesslevel, profile, clientip
Explanation
An administrative user has logged in.
Gateway Action
None
Action Description
None
Proposed Action
None

2.44.2. [ID: 297] Incorrect user name or insufficient[...]

Log Categories
SSHD
Log Message
Incorrect user name or insufficient credentials.
Default Log Severity
Warning
Parameters
user, method, accesslevel, profile, clientip, sshserver
Explanation
Administrative user login have been aborted. This is due to user not existing or having insufficient privileges.
Gateway Action
Close
Action Description
None
Proposed Action
Increase user privileges or change the access level of the SSH server.

2.44.3. [ID: 186] Administrative user failed to login because[...]

Log Categories
SSHD
Log Message
Administrative user failed to login because of bad credentials.
Default Log Severity
Warning
Parameters
user, method, accesslevel, profile, clientip
Explanation
An administrative user failed to log in to configuration system. This is most likely due to an invalid entered username or password, or incorrect public key authentication.
Gateway Action
Close
Action Description
None
Proposed Action
None

2.44.4. [ID: 455] Administrative user logged out

Log Categories
SSHD
Log Message
Administrative user logged out.
Default Log Severity
Notice
Parameters
user, method, accesslevel, profile, clientip
Explanation
An administrative user has logged out.
Gateway Action
None
Action Description
None
Proposed Action
None

2.44.5. [ID: 1287] Fatal sshd error

Log Categories
SSHD
Log Message
Fatal sshd error.
Default Log Severity
Warning
Parameters
clientip, sshserver, reason
Explanation
The connection attempt was aborted due to internal error.
Gateway Action
Close
Action Description
Nonen
Proposed Action
None

2.44.6. [ID: 877] Failed to get traffic parameters from[...]

Log Categories
SSHD
Log Message
Failed to get traffic parameters from dataplane.
Default Log Severity
Notice
Parameters
clientip, sshserver
Explanation
This is a problem with the internal communication within the system.
Gateway Action
Close
Action Description
None
Proposed Action
None

2.44.7. [ID: 474] SSH session inactivity time limit has been[...]

Log Categories
SSHD
Log Message
SSH session inactivity time limit has been reached.
Default Log Severity
Warning
Parameters
time, clientip, sshserver
Explanation
The connect client has been inactive for too long, and is forcibly logged out.
Gateway Action
Close
Action Description
None
Proposed Action
Increase the inactive session timeout value if it is set too low.

2.44.8. [ID: 448] Username change

Log Categories
SSHD
Log Message
Username change.
Default Log Severity
Warning
Parameters
service, old, clientip
Explanation
User changed the service between two authentication phases, which is not allowed.
Gateway Action
Close
Action Description
None
Proposed Action
None

2.44.9. [ID: 256] Invalid service request received

Log Categories
SSHD
Log Message
Invalid service request received.
Default Log Severity
Warning
Parameters
clientip, service
Explanation
A invalid service request was received.
Gateway Action
Close
Action Description
None
Proposed Action
Investigate why the SSH client is sending a invalid service request.

2.44.10. [ID: 576] Username change

Log Categories
SSHD
Log Message
Username change.
Default Log Severity
Warning
Parameters
user, old, clientip
Explanation
User changed the username between two authentication phases, which is not allowed.
Gateway Action
Close
Action Description
None
Proposed Action
None

2.44.11. [ID: 425] SSH Login grace timeout expired

Log Categories
SSHD
Log Message
SSH Login grace timeout expired.
Default Log Severity
Warning
Parameters
time, clientip
Explanation
The client failed to login within the given login grace time.
Gateway Action
Close
Action Description
None
Proposed Action
Increase the grace timeout value if it is set too low.

2.44.12. [ID: 554] Maximum number of authentication retries[...]

Log Categories
SSHD
Log Message
Maximum number of authentication retries reached.
Default Log Severity
Error
Parameters
user, clientip
Explanation
User failed to authenticate within the maximum allowed number of tries.
Gateway Action
Close
Action Description
None
Proposed Action
None

2.44.13. [ID: 225] The maximum number of simultaneously[...]

Log Categories
SSHD
Log Message
The maximum number of simultaneously connected SSH clients has been reached.
Default Log Severity
Warning
Parameters
max, clientip, sshserver
Explanation
The maximum number of simultaneously connected SSH clients has been reached. Denying access for this attempt, and closing the connection.
Gateway Action
Close
Action Description
None
Proposed Action
Wait until an existing connection has closed or increase the number of allowed connections.

2.44.14. [ID: 406] The maximum number of connection attempts[...]

Log Categories
SSHD
Log Message
The maximum number of connection attempts reached.
Default Log Severity
Warning
Parameters
max, clientip, sshserver
Explanation
The maximum number of connection attempts have been reached.
Gateway Action
Close
Action Description
None
Proposed Action
Wait until an existing connection has closed or increase the number of allowed connections.

2.44.15. [ID: 640] Incompatible encryption

Log Categories
SSHD
Log Message
Incompatible encryption.
Default Log Severity
Warning
Parameters
clientip, sshserver, reason
Explanation
The connection attempt was aborted due to incompatible ciphers between server and client.
Gateway Action
Close
Action Description
None
Proposed Action
Ensure that client and server are using compatible ciphers.

2.44.16. [ID: 1293] Incompatible key exchange algorithm

Log Categories
SSHD
Log Message
Incompatible key exchange algorithm.
Default Log Severity
Warning
Parameters
clientip, sshserver, reason
Explanation
The connection attempt was aborted due to incompatible key exchange algorithms between server and client.
Gateway Action
Close
Action Description
None
Proposed Action
Ensure that client and server are using compatible key exchange algorithm.

2.44.17. [ID: 639] Incompatible mac

Log Categories
SSHD
Log Message
Incompatible mac.
Default Log Severity
Warning
Parameters
clientip, sshserver, reason
Explanation
The connection attempt was aborted due to incompatible macs between server and client.
Gateway Action
Close
Action Description
None
Proposed Action
Ensure that client and server are using compatible macs.

2.44.18. [ID: 996] Request to copy file

Log Categories
SSHD
Log Message
Request to copy file.
Default Log Severity
Information
Parameters
 
Explanation
Request to copy files was successful.
Gateway Action
None
Action Description
None
Proposed Action
None

2.44.19. [ID: 995] Request to copy file failed

Log Categories
SSHD
Log Message
Request to copy file failed.
Default Log Severity
Warning
Parameters
 
Explanation
Request to copy file failed.
Gateway Action
None
Action Description
None
Proposed Action
None

2.44.20. [ID: 994] Request to copy file successful

Log Categories
SSHD
Log Message
Request to copy file successful.
Default Log Severity
Information
Parameters
 
Explanation
Request to copy a file.
Gateway Action
None
Action Description
None
Proposed Action
None

2.44.21. [ID: 624] SSH connection is no longer valid

Log Categories
SSHD
Log Message
SSH connection is no longer valid.
Default Log Severity
Notice
Parameters
clientip, sshserver
Explanation
The SSH connection is no longer valid. The might be a result of the SSH management object being changed.
Gateway Action
Close
Action Description
None
Proposed Action
None

2.44.22. [ID: 997] Closing session for subsystem

Log Categories
SSHD
Log Message
Closing session for subsystem.
Default Log Severity
Information
Parameters
subsystem
Explanation
Closing the session for subsystem.
Gateway Action
None
Action Description
None
Proposed Action
None

2.44.23. [ID: 993] Creating session for subsystem request

Log Categories
SSHD
Log Message
Creating session for subsystem request.
Default Log Severity
Information
Parameters
subsystem
Explanation
Creating a session for the requested subsystem.
Gateway Action
None
Action Description
None
Proposed Action
None