Results 1 to 6 of 6

Thread: SSH blocked?

  1. #1
    Junior Member
    Join Date
    Mar 2007
    Posts
    3

    SSH blocked?

    Hi,

    I'm live booting on machine with view to doing an HD install
    Machine is currently running (almost, refusing to boot anymore) Xandros linux.

    Problem:
    SSH to the live boot machine(DHCP'd 10.1.0.44 ) doesn't work.
    No error message, just ssh hangs forever ( does even show a login prompt )
    Tried from a Windows machine using putty and from DamnSmall Linux using just ssh
    Both machines can ping 10.1.0.44 and it can ping them.
    ssh on 10.1.0.44 to DamnSmall linux machine also hangs ( Window putty to DSL works ).

    Netstat on machine shows I have started sshd and it's listening ( 10.1.0.44:ssh *:* LISTEN )
    KNOPPIX Firewall is reporting as "Firewall Active? no"
    from 10.1.0.44 I can do: ssh 10.1.0.44 and it connects okay.
    Running a Port Scan from 10.1.0.44 to 10.1.0.44 shows ssh open.
    Running a Port Scan from 10.1.0.44 to DSL machine also shows ssh open.

    Any ideas?
    Is there another firewall somewhere?

    NOTE: Also Icewasel is not able to connect to web server on DSL machine. It's looking like it TCP that's not working a UDP/ICMP is? (ie ping works)
    Is it something in the /etc/ssh/sshd-config that I can't spot that's stopping it working?

  2. #2
    Senior Member registered user
    Join Date
    Apr 2005
    Posts
    159
    you first need to generate host keys and start the daemon with "/etc/init.d/ssh start" (as root).

  3. #3
    Junior Member
    Join Date
    Mar 2007
    Posts
    3
    I believe those keys were created when I ran the sshstart script.
    In /etc/ssh I have:
    moduli
    primes
    ssh_config
    ssh_host_dsa_key
    ssh_host_dsa_key.pub
    ssh_host_key
    ssh_host_key.pub
    ssh_host_rsa_key
    ssh_host_rsa_key.pub
    sshd_config

    I reboot and started again and re-run that script, changed root passwd and it's made no difference.
    Can still ping but not ssh to or from the live boot machine.

  4. #4
    Senior Member registered user
    Join Date
    Apr 2004
    Location
    Germany
    Posts
    100
    Try ssh -v . This increases the verbosity of the client - perhaps it will tell you what's missing.

  5. #5
    Junior Member
    Join Date
    Mar 2007
    Posts
    3
    Good suggestion, not sure if this helps anyone.

    This is trying to ssh to the live boot Knoppix 5.1.1 ( Current Linux Mag Cover disk. Issue 77 )
    Trying from DamnSmall Linux:
    root@0[root]# ssh -v 10.1.0.44
    OpenSSH_3.6.1p2 Debian 1:3.6.1p2-9, SSH protocols 1.5/2.0, OpenSSL 0x0090705f
    debug1: Reading configuration data /etc/ssh/ssh_config
    debug1: Applying options for *
    debug1: /etc/ssh/ssh_config line 17: Deprecated option "FallBackToRsh"
    debug1: /etc/ssh/ssh_config line 18: Deprecated option "UseRsh"
    debug1: Rhosts Authentication disabled, originating port will not be trusted.
    debug1: Connecting to 10.1.0.44 [10.1.0.44] port 22.
    debug1: Connection established.
    debug1: read PEM private key done: type DSA
    debug1: read PEM private key done: type RSA
    debug1: identity file /root/.ssh/identity type -1
    debug1: identity file /root/.ssh/id_rsa type -1
    debug1: identity file /root/.ssh/id_dsa type -1

    Try to go from Knoppix back back to the DamnSmall linux machine:
    # ssh -v 10.1.0.10
    Basically the lines with errors are:
    debug1: An invalid name was supplied
    Cannot determine realm for numeric host address

    debug1: An invalid name was supplied
    A parameter was malformed
    Validation error

    debug1: SSH2_MSG_KEXINIT sent
    -----------------------------------------------------------

    Giving the machines names in /etc/hosts made no difference.

  6. #6
    Senior Member registered user
    Join Date
    Apr 2004
    Location
    Germany
    Posts
    100
    >debug1: An invalid name was supplied

    I don't know if 'name' means username, but just to make sure try
    ssh username@10.1.0.10
    where 'username' is a valid account on 10.1.0.10 .

    You might also try to step up ssh's verbosity by increasing the amount of 'v's
    up to three (ssh -vvv).

    Consider running sshd on 10.1.0.10 with -D or -d options (man sshd for details)
    to see what's going on on the other side of the connection.

    (P.S. I won't be reading this forum before Mon 12th again, just in case you
    wonder why I've stopped responding :-)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  


New Precision DWDM SFP+ 10G 80km Tunable Transceiver 50GHz C-Temp DWDM-SFP10G-C picture

New Precision DWDM SFP+ 10G 80km Tunable Transceiver 50GHz C-Temp DWDM-SFP10G-C

$90.00



LOT OF 20 Genuine Cisco SFP-10G-SR V03 10GBASE-SR SFP+ Transceiver Module picture

LOT OF 20 Genuine Cisco SFP-10G-SR V03 10GBASE-SR SFP+ Transceiver Module

$95.00



10 PCS Cisco GLC-LH-SMD 10-2625-01 1310nm SFP Transceiver Module picture

10 PCS Cisco GLC-LH-SMD 10-2625-01 1310nm SFP Transceiver Module

$85.00



Lot (10) Dell 0N8TDR 850nm SFP-10G-SR-85C 10Gbs sfp+ FTLX8574D3BNL-FC N8TDR NEW picture

Lot (10) Dell 0N8TDR 850nm SFP-10G-SR-85C 10Gbs sfp+ FTLX8574D3BNL-FC N8TDR NEW

$68.00



Brand New Cisco GLC-LH-SMD 1000BASE-LX/LH SFP Module 1310nm 10km SMF LC picture

Brand New Cisco GLC-LH-SMD 1000BASE-LX/LH SFP Module 1310nm 10km SMF LC

$9.50



Genuine Cisco SFP-10G-SR V03 10GBASE-SR SFP+ Transceiver Module 10-2415-03  picture

Genuine Cisco SFP-10G-SR V03 10GBASE-SR SFP+ Transceiver Module 10-2415-03

$8.00



Cisco SFP-10G-LR 10-2457-02 V02 10GBASE-LR SFP+ TRASNCEIVER COMPATIBLE picture

Cisco SFP-10G-LR 10-2457-02 V02 10GBASE-LR SFP+ TRASNCEIVER COMPATIBLE

$19.90



CISCO SFP-10G-LR SFP TRANSCEIVER MODULE GBIC  10G 10GB SFP - 1 Year Warranty picture

CISCO SFP-10G-LR SFP TRANSCEIVER MODULE GBIC 10G 10GB SFP - 1 Year Warranty

$39.99



Nvida Mellanox MC3208411-T 1000GBASE-T SFP-TX 100m Optical 1GbE Base-T RJ45 New picture

Nvida Mellanox MC3208411-T 1000GBASE-T SFP-TX 100m Optical 1GbE Base-T RJ45 New

$27.95



SFP-10G-SR CISCO 10G SR SFP+ C-CLASS TRANSCEIVER 10 PACK picture

SFP-10G-SR CISCO 10G SR SFP+ C-CLASS TRANSCEIVER 10 PACK

$99.00