Originally posted by: Tibor_B
Hi,
Our syslog shows unexplained ssh connection between our 2 servers, like:
Sep 9 03:16:09 serverX auth|security:info sshd[53739966]: Accepted publickey for oracle from 10.1.2.3 port 39066 ssh2
There is always a bunch of such connections every day early morning. Both servers hosts oracle databases, they have to communicate, but not via ssh service. Also our oracle admins claim there should be no ssh communication this way.
Connections are shortliving, in fact I would say not successful because .profile requires user's response.
Both servers are production, so I cannot ban such connections or otherwise endanger their operations.
What can I do?
F.e. can I find what processes opened the ssh connections? (I repeat, they are shortliving connections)
Any ideas welcommed, thanks...
#AIX-Forum