Help answer threads with 0 replies.
Go Back > Forums > Linux Forums > Linux - Newbie
User Name
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!


  Search this Thread
Old 05-09-2015, 07:17 PM   #1
LQ Newbie
Registered: Feb 2015
Posts: 2

Rep: Reputation: Disabled
Question Wrong incoming ssh ports in /var/log/auth.log ?

I am using my raspberry pi with Linux 3.18+ installed. I changed the default ssh port from 22 to 16022. This is my sshd_config file:
# Package generated configuration file
# See the sshd_config(5) manpage for details

# What ports, IPs and protocols we listen for
#Port 22
Port 16022
# Use these options to restrict which interfaces/protocols sshd will bind to
#ListenAddress ::
Protocol 2
PAM auth is disabled and I only login using password. Now, I checked the authentication log file: /var/log/auth.log. This is a snippet of what it contains:
Apr 23 23:44:55 raspberrypi sshd[6473]: Accepted password for pi from port 51978 ssh2
Apr 23 23:52:22 raspberrypi sshd[6477]: Received disconnect from 11: Normal Shutdown
May 5 01:51:02 raspberrypi sshd[4551]: Accepted password for pi from port 30222 ssh
May 5 09:43:47 raspberrypi sshd[6033]: Accepted password for pi from port 21551 ssh2
May 5 09:43:53 raspberrypi sshd[6039]: Received disconnect from 11: Normal Shutdown
May 5 14:09:23 raspberrypi sshd[6783]: Accepted password for pi from port 28684 ssh
May 5 14:32:43 raspberrypi sshd[7008]: Accepted password for pi from port 28689 ssh
May 5 14:37:21 raspberrypi sshd[7014]: Received disconnect from 11: Normal Shutdow
May 8 02:01:41 raspberrypi sshd[24468]: Accepted password for pi from port 30862 ssh2
How is this possible? Why is it showing these random ports for ssh?

This is what 'sudo netstat -nlp' gives:
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address           Foreign Address         State       PID/Program name
tcp        0      0*               LISTEN      7923/0
tcp        0      0 *               LISTEN      2501/sshd
udp        0      0 *                           2019/dhclient
udp        0      0    *                           2192/dhclient
udp        0      0    *                           2019/dhclient
udp        0      0*                           2419/ntpd
udp        0      0*                           2419/ntpd
udp        0      0 *                           2419/ntpd
udp        0      0   *                           2419/ntpd
udp        0      0 *                           2192/dhclient
Active UNIX domain sockets (only servers)
Proto RefCnt Flags       Type       State         I-Node   PID/Program name    Path
unix  2      [ ACC ]     SEQPACKET  LISTENING     3880     168/udevd           /run/udev/control
unix  2      [ ACC ]     STREAM     LISTENING     8018     2341/dbus-daemon    /var/run/dbus/system_bus_socket
Plus, I am accessing my machine from outside my home network. My router is configured to block all ports, except 16022, whose tcp traffic is forwarded to my raspberry pi. So I don't understand why the log file has these weird ports listed.
Old 05-10-2015, 12:39 PM   #2
Registered: Nov 2012
Posts: 188

Rep: Reputation: 60
These random ports are the ports used by your ssh client, not your server. The server is always listening on port 16022 but when it sends data to the client it is getting sent to a different port on the client machine which will change each time you make a new connection.
1 members found this post helpful.
Old 05-10-2015, 03:02 PM   #3
LQ Newbie
Registered: Feb 2015
Posts: 2

Original Poster
Rep: Reputation: Disabled
I see. thanks for the explanation.


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Perl or PHP Script that can tail /var/log/auth.log - two-factor authentication tdnnash25 Linux - Server 1 06-18-2009 08:36 PM
the significance and name of the 5th column of /var/log/auth.log (ubuntu server)? CoffeeKing!!! Linux - Security 4 02-05-2009 07:32 AM
What the %$#@ is pam_unix (cron:session) doing every ten minutes? (/var/log/auth.log) CoffeeKing!!! Linux - Security 3 02-05-2009 07:07 AM
/var/log/auth.log doens't have correct date and hostname (Solution) alfmarius Linux - Newbie 0 10-07-2008 06:09 AM
weird stuff in /var/log/auth.log bschiett Linux - Security 3 03-12-2005 08:29 AM

All times are GMT -5. The time now is 04:10 AM.

Main Menu
Write for LQ is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration