Event 4625 - Logon Failure - Server 2008 R2 is logging them all over the place ! How to stop the attack?
Posted
by
user72593
on Server Fault
See other posts from Server Fault
or by user72593
Published on 2011-03-01T07:12:55Z
Indexed on
2011/03/01
7:26 UTC
Read the original article
Hit count: 162
server
|windows-server-2008-r2
I've been monitoring failed logons to a server which is directly connected to the internet with no hardware firewall in the way...testing purposes only. Using the Server 2008 R2 firewall, I blocked access to just about everything except RDP, then I told the firewall to only allow connections to the RDP port from "MY" static IP. I tested from other locations and I am not able to login to the server unless i'm at my office. So how are people coming from Chinese IP's able to attempt logons and get logged as failures ?? Is there something i'm missing that needs to be blocked? Any help would be appreciated.
© Server Fault or respective owner