I set up an IP range that excludes the firewall.
For example:
192.168.15.1 - 192.168.15.240
192.168.15.242 - 192.168.15.254
So 241, the firewall, is left out.
I still got the ssh login attempt. Interestingly some minutes after scanning is finished.
I will try some other changes next week. Thanks so long for your support.
Bruce.B wrote:
Scanning exclusions, especially asset type exclusions will not prevent all scanning queries from being sent. For asset type exclusions specifically this is due to the scanning logic having to first identify the asset's type, which may involve SSH queries. Scanning exclusions will prevent scanned data from being added after the exclusion is added.
If you want to be certain SSH isn't used to authenticate, I'd recommend instead modifying the IP Range scanning target that contains this device via Scanning\Scanning Targets and enabling the No SSH option. If the IP Range contains devices that you would like SSH to be used for, you'll need to split up the IP Range into multiple ranges first. Create as many smaller ranges as are necessary and delete the larger range.