Re: Re[2]: can't ssh to remote FreeBSD machine

From: Subhash Gopinath (subhashg_at_gmail.com)
Date: 02/28/05

  • Next message: John: "Re: can't ssh to remote FreeBSD machine"
    Date: Sun, 27 Feb 2005 15:59:54 -0800
    To: Hexren <me@hexren.net>
    
    

    Hi,

    When I executed ipfw on the FreeBSD machine ... I get this result -

    >ipfw show
    ipfw: getsockopt(IP_FW_GET) : Protocol not available

    Is there any other firewall that I need to look at ?

    tx,
    Subhash

    On Mon, 28 Feb 2005 00:50:23 +0100, Hexren <me@hexren.net> wrote:
    > SG> Hi,
    >
    > SG> Results are the same when I try with a non-super-user account (say guest)..
    > SG> Btw, I have set PermitRootLogin=yes in /etc/ssh/sshd_config
    >
    > SG> tx,
    > SG> Subhash
    >
    > SG> On Sun, 27 Feb 2005 15:25:10 -0600, Kevin Kinsey <kdk@daleco.biz> wrote:
    > >> Subhash Gopinath wrote:
    > >>
    > >> >Hi,
    > >> >
    > >> >Here's the debug o/p of ssh ('have replaced the IP address with a dummy one...)
    > >> >
    > >> >-bash-2.05b$ ssh -vv root@A.B.C.D
    > >> >
    > >> >
    > >>
    > >> Read on....
    > >>
    > >> >OpenSSH_3.7.1p2, SSH protocols 1.5/2.0, OpenSSL 0.9.7d 17 Mar 2004
    > >> >debug1: Reading configuration data /etc/ssh/ssh_config
    > >> >debug1: Applying options for *
    > >> >debug2: ssh_connect: needpriv 0
    > >> >debug1: Connecting to A.B.C.D [A.B.C.D] port 22.
    > >> >
    > >> >And it stops at this point...But the machine is Up (since I can ping
    > >> >it) and sshd is running on port 22
    > >> >
    > >> >Thanks,
    > >> >Subhash
    > >> >
    > >> >On Sun, 27 Feb 2005 10:03:05 +0200, Ion-Mihai Tetcu
    > >> ><itetcu@people.tecnik93.com> wrote:
    > >> >
    > >> >
    > >> >>Do a ssh -vvv user@machine and see the output. Note that user root can't
    > >> >>connect by ssh by default for security reasons.
    > >> >>
    > >> >>
    > >>
    > >> As Ion-Mihail said in the sentence about this one, you can't ssh
    > >> root@anybox
    > >> (by default, it is *not* allowed).
    > >>
    > >> Kevin Kinsey
    > >>
    >
    > ---------------------------------------------
    >
    > You have made sure that there is no firewall blocking ssh from the
    > outside ?
    >
    > Hexren
    >
    >
    _______________________________________________
    freebsd-newbies@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-newbies
    To unsubscribe, send any mail to "freebsd-newbies-unsubscribe@freebsd.org"


  • Next message: John: "Re: can't ssh to remote FreeBSD machine"

    Relevant Pages

    • [fw-wiz] UNSUBSCRIBE
      ... (Paul D. Robertson) ... > fixup protocol icmp error ... >> isn't about the security properties of the control, ... errors in the firewall, configuration errors, and it then takes physical ...
      (Firewall-Wizards)
    • Re: [fw-wiz] Secure Computing Sidewinder?
      ... We are moving off Sidewinder G2 solely because of the price. ... There are many different approaches to designing a firewall, ... thorough than most other "application proxy" firewalls, ... packet, tear it apart, inspects it, and then depending on the protocol it ...
      (Firewall-Wizards)
    • Re: Natted IP
      ... > useful if one trys to tunnel an exploit of one protocol inside a second ... but the router "firewall" will block all unsolicited packets unles they are ... If you send some kind of tunneled packet wrapped inside, ... > run only with JS enabled with Java applets disabled. ...
      (alt.computer.security)
    • Firewall that blocks NetBEUI etc.
      ... Personal firewall functionality is mostly oriented toward TCP/IP protocol. ... I have NT4WKS and we have advanced Microsoft network - they have some tool ... I have tried to audit them with netstat or TCPview to see all network ...
      (comp.security.firewalls)
    • Re: Ports getting hammered?
      ... >>> If your Watchguard can't stop outbound traffic... ... >>> Would not the Windows XP firewall do exactly the same work? ... >> protocol analysis to see if protocols are being broken only a IDS ... > permitted ports and protocols. ...
      (comp.security.firewalls)