Frequent ‘security.invalid.login’ Errors Due to Stale BlueXP connection
Applies to
- ONTAP 9
- BlueXP (NetApp Console)
- On-premises environments using BlueXP to manage ONTAP clusters
Issue
- The ONTAP cluster event logs are repeatedly filled with
security.invalid.loginerrors for the ‘admin’ user. These failed login attempts originate from specific IP addresses associated with BlueXP and other management systems, causing the ‘admin’ account to be locked out after repeated failures. - Example EMS log output:
security.invalid.login: error - User 'admin' from IP 192.168.1.100 attempted to log in via REST API - Authentication failed.security.invalid.login: error - User 'admin' from IP 192.168.1.101 attempted to log in via CLI - Authentication failed.
- The errors persisted even after removing and re-adding the cluster to BlueXP with a different user.
- The retries originated from the BlueXP agent VM IP.
- The system event log filled up and the ‘admin’ account was repeatedly locked.
