Linux - NetworkingThis forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.
Notices
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
If you have any problems with the registration process or your account login, please contact us. If you need to reset your password, click here.
Having a problem logging in? Please visit this page to clear all LQ-related cookies.
Get a virtual cloud desktop with the Linux distro that you want in less than five minutes with Shells! With over 10 pre-installed distros to choose from, the worry-free installation life is here! Whether you are a digital nomad or just looking for flexibility, Shells can put your Linux machine on the device that you want to use.
Exclusive for LQ members, get up to 45% off per month. Click here for more info.
I have a strange ssh problem. I'm running the 2.6.9 kernel on a gentoo box, naturally, with the sshd going for remote administration. The gentoo box is acting as a router and firewall for my small subnet, both being done by iptables.
The problem occurs when I try to ssh into the box from the internet. I can ssh into the box fine from anywhere inside the local subnet (eth1), but any connection coming into eth0 seems to hang.
The client connects, and the server registers the connection, it then asks for the password for the given user. If an incorrect password is entered, it tells you and asks again. So far, so good. The problem arises if the correct password is entered. No prompt appears. It just hangs. Eventually, after about 10 minutes (might be longer, I've not bothered to time it) it times out. However, the /var/log/everything/current file shows that the session is successfully opened - it just never gets to the client.
This is not a firewall issue, as it makes no difference as to whether the firewall is active or not.
Wanting to debug this problem further, I set up the sshd as a standalone non-daemon process listening on port 1745. I also turned debug mode on so I could see what it was doing. Also, I ran the client with -v -v -v which I believe turns on the highest debugging level. Apologies for not posting links, apparently I'm not allowed to.
What the server said:
debug1: sshd version OpenSSH_3.8.1p1
debug1: read PEM private key done: type RSA
debug1: private host key: #0 type 1 RSA
debug1: read PEM private key done: type DSA
debug1: private host key: #1 type 2 DSA
debug1: Bind to port 1745 on 0.0.0.0.
Server listening on 0.0.0.0 port 1745.
socket: Address family not supported by protocol
debug1: Server will not fork when running in debugging mode.
Connection from 131.111.179.82 port 33802
debug1: Client protocol version 2.0; client software version OpenSSH_3.4p1 Debia
n 1:3.4p1-1.woody.3
debug1: match: OpenSSH_3.4p1 Debian 1:3.4p1-1.woody.3 pat OpenSSH*
debug1: Enabling compatibility mode for protocol 2.0
debug1: Local version string SSH-2.0-OpenSSH_3.8.1p1
debug1: permanently_set_uid: 22/22
debug1: list_hostkey_types: ssh-rsa,ssh-dss
debug1: SSH2_MSG_KEXINIT sent
debug1: SSH2_MSG_KEXINIT received
debug1: kex: client->server aes128-cbc hmac-md5 none
debug1: kex: server->client aes128-cbc hmac-md5 none
debug1: SSH2_MSG_KEX_DH_GEX_REQUEST received
debug1: SSH2_MSG_KEX_DH_GEX_GROUP sent
debug1: expecting SSH2_MSG_KEX_DH_GEX_INIT
debug1: SSH2_MSG_KEX_DH_GEX_REPLY sent
debug1: SSH2_MSG_NEWKEYS sent
debug1: expecting SSH2_MSG_NEWKEYS
debug1: SSH2_MSG_NEWKEYS received
debug1: KEX done
debug1: userauth-request for user growse service ssh-connection method none
debug1: attempt 0 failures 0
debug1: PAM: initializing for "growse"
debug1: PAM: setting PAM_RHOST to "student.cusu.cam.ac.uk"
debug1: PAM: setting PAM_TTY to "ssh"
Failed none for growse from 131.111.179.82 port 33802 ssh2
Failed none for growse from 131.111.179.82 port 33802 ssh2
debug1: userauth-request for user growse service ssh-connection method keyboard-
interactive
debug1: attempt 1 failures 1
debug1: keyboard-interactive devs
debug1: auth2_challenge: user=growse devs=
debug1: kbdint_alloc: devices 'pam'
debug1: auth2_challenge_start: trying authentication method 'pam'
Postponed keyboard-interactive for growse from 131.111.179.82 port 33802 ssh2
debug1: PAM: num PAM env strings 0
Postponed keyboard-interactive/pam for growse from 131.111.179.82 port 33802 ssh
2
Accepted keyboard-interactive/pam for growse from 131.111.179.82 port 33802 ssh2
debug1: monitor_child_preauth: growse has been authenticated by privileged proce
ss
Accepted keyboard-interactive/pam for growse from 131.111.179.82 port 33802 ssh2
debug1: PAM: reinitializing credentials
debug1: permanently_set_uid: 1000/100
debug1: Entering interactive session for SSH2.
debug1: server_init_dispatch_20
debug1: server_input_channel_open: ctype session rchan 0 win 65536 max 16384
debug1: input_session_request
debug1: channel 0: new [server-session]
debug1: session_new: init
debug1: session_new: session 0
debug1: session_open: channel 0
debug1: session_open: session 0: link with channel 0
debug1: server_input_channel_open: confirm session
debug1: server_input_channel_req: channel 0 request pty-req reply 0
debug1: session_by_channel: session 0 channel 0
debug1: session_input_channel_req: session 0 req pty-req
debug1: Allocating pty.
debug1: session_new: init
debug1: session_new: session 0
debug1: session_pty_req: session 0 alloc /dev/pts/5
debug1: server_input_channel_req: channel 0 request shell reply 0
debug1: session_by_channel: session 0 channel 0
debug1: session_input_channel_req: session 0 req shell
debug1: PAM: setting PAM_TTY to "/dev/pts/5"
debug1: Setting controlling tty using TIOCSCTTY.
# This is the sshd server system-wide configuration file. See
# sshd_config(5) for more information.
# This sshd was compiled with PATH=/usr/bin:/bin:/usr/sbin:/sbin
# The strategy used for options in the default sshd_config shipped with
# OpenSSH is to specify options with their default value where
# possible, but leave them commented. Uncommented options change a
# default value.
Port 1745
Protocol 2
#ListenAddress 0.0.0.0
#ListenAddress ::
# HostKey for protocol version 1
#HostKey /etc/ssh/ssh_host_key
# HostKeys for protocol version 2
#HostKey /etc/ssh/ssh_host_rsa_key
#HostKey /etc/ssh/ssh_host_dsa_key
# Lifetime and size of ephemeral version 1 server key
#KeyRegenerationInterval 1h
#ServerKeyBits 768
# Logging
#obsoletes QuietMode and FascistLogging
#SyslogFacility AUTH
#LogLevel INFO
# For this to work you will also need host keys in /etc/ssh/ssh_known_hosts
#RhostsRSAAuthentication no
# similar for protocol version 2
#HostbasedAuthentication no
# Change to yes if you don't trust ~/.ssh/known_hosts for
# RhostsRSAAuthentication and HostbasedAuthentication
#IgnoreUserKnownHosts no
# Don't read the user's ~/.rhosts and ~/.shosts files
#IgnoreRhosts yes
# To disable tunneled clear text passwords, change to no here!
#PasswordAuthentication yes
#PermitEmptyPasswords no
# Change to no to disable s/key passwords
#ChallengeResponseAuthentication yes
# Kerberos options
#KerberosAuthentication no
#KerberosOrLocalPasswd yes
#KerberosTicketCleanup yes
#KerberosGetAFSToken no
# GSSAPI options
#GSSAPIAuthentication no
#GSSAPICleanupCredentials yes
# Set this to 'yes' to enable PAM authentication (via challenge-response)
# and session processing. Depending on your PAM configuration, this may
# bypass the setting of 'PasswordAuthentication' and 'PermitEmptyPasswords'
UsePAM yes
#AllowTcpForwarding yes
#GatewayPorts no
#X11Forwarding no
#X11DisplayOffset 10
#X11UseLocalhost yes
#PrintMotd yes
#PrintLastLog yes
#TCPKeepAlive yes
#UseLogin no
#UsePrivilegeSeparation yes
#PermitUserEnvironment no
#Compression yes
#ClientAliveInterval 0
#ClientAliveCountMax 3
#UseDNS yes
#PidFile /var/run/sshd.pid
#MaxStartups 10
# no default banner path
#Banner /some/path
# override default of no subsystems
Subsystem sftp /usr/lib/misc/sftp-server
Can you transfer files between your server and the remote client?
Try "netcat -l -p 1234" on the server and "dd if=/dev/zero bs=4k count=100|netcat <server> 1234"
Does the shell start running on the server?
What is in your pam files?
Well after checking the logs there are a few things that I saw that caught my attention and says that no such keys check under those directories if u have these keys generated if not then use the cmd key-gen to generate new keys if needed.
ebug3: authmethod_is_enabled publickey
debug1: next auth method to try is publickey
debug1: try privkey: /home/hrn21/.ssh/identity
debug3: no such identity: /home/hrn21/.ssh/identity
debug1: try privkey: /home/hrn21/.ssh/id_rsa
debug3: no such identity: /home/hrn21/.ssh/id_rsa
debug1: try privkey: /home/hrn21/.ssh/id_dsa
debug3: no such identity: /home/hrn21/.ssh/id_dsa
debug2: we did not send a packet, disable method
In your sshd conf file choose the type keys u want to use for the authentication by activating the following
# HostKey for protocol version 1
#HostKey /etc/ssh/ssh_host_key
HostKeys for protocol version 2
HostKey /etc/ssh/ssh_host_rsa_key
HostKey /etc/ssh/ssh_host_dsa_key
Futher down the sshd config file place the following
I don't think that it is related to public key auth. You seem to be authenticating fine. I haven't seen this problem before, but here are some more things to look at:
What's in /etc/pam.d/system-auth (that's what the pam_stack module does)? Did you try it with UsePAM No in sshd_config?
What processes are started on the server?
Could increase the debug level (-ddd) on sshd?
Can the client ssh to other places? Do you have a different host to ssh from?
Turns out to be the fault of the modem. I cam across this page: http://www.magwag.plus.com/jim/tips-300t.html which describes the same problem as me with the same modem. I just need to set the output tos to 0x0 and it's all fine. Tested it and everything
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.