Re: SSH timing out



__/ [ Aaron Gray ] on Saturday 25 February 2006 18:42 \__

We have two remote servers both RedHat 9. One times out on SSH the other
does not.


My initial, instinctive gut feeling: firewall. I have been down that route
before. Check firewall policies and attempt to temporarily disable it.


How do I stop the one timing out from doing so ?

It's difficult to say, but could look at your /etc/ssh/sshd_config and
enable TCPKeepAlive on the server,

TCPKeepAlive yes

It does not appear to be in '/etc/ssh/sshd_config' as this is the same on
both systems.

sshd_config config file has a KeepAlive but no TCPKeepAlive, so I tried
both, neither works.


I wouldn't have thought that descending to that level was necessary.


If the problem would be client side, then look at the /etc/ssh/ssh_config,
there you find ConnectTimeout, setting this to 0 should prevent client
side disconects

ConnectTimeout 0


But there can still be other problems like a bed gateway in between, which
can cause the connection to break, but thats not so common.

Yes it could possibly be the firewall router box on that server ?


If the firewall is controlled by an intermediatery box, try some simpler SSH
tests that go in different routes. Try other remote connections like telnet
if necessary, even ping just to ensure nothing more fundamental is
preventing a connection.

Roy
.



Relevant Pages

  • Re: Win 2003
    ... Default gateway 192.168.200.1 My firewall ... There is nothing blocking things on the firewall. ... Server is a member of the domain. ... IPv4 Route Table ...
    (microsoft.public.windows.server.general)
  • Re: vsftpd as an Anonymous FTP server
    ... Your server hasn't got your firewall set up as the default route - the ... Are there any entries in /var/log/vsftpd.log ...
    (alt.os.linux.suse)
  • Re: static route
    ... Server needs to access Server thru ... The firewall rule has been defined to allow ... traffic from source to target. ... and set 10.10.10.40 as the gateway for that route. ...
    (microsoft.public.windows.server.networking)
  • Re: SSH timing out
    ... I have been down that route ... Check firewall policies and attempt to temporarily disable it. ... there you find ConnectTimeout, setting this to 0 should prevent client ... It may well be the firewall router as this is different from my second site ...
    (alt.linux)
  • Re: direct traffic to second webserver
    ... ISA would be able to route according to host header: ... then another alternative such as binding a second IP to the firewall that is automatically forwarded to port 80 on Web Server 2 would work. ... currently our firewall directs all incoming port 80 traffic to server ...
    (microsoft.public.windows.server.sbs)