Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #241567 > unrolled thread

Re: openssh server remote access

Started bySemih Ozlem <semihozlemlinuxuser@gmail.com>
First post2021-10-21 22:50 +0200
Last post2021-10-22 19:20 +0200
Articles 15 — 8 participants

Back to article view | Back to linux.debian.user

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Re: openssh server remote access Semih Ozlem <semihozlemlinuxuser@gmail.com> - 2021-10-21 22:50 +0200
    Re: openssh server remote access Joe <joe@jretrading.com> - 2021-10-21 23:10 +0200
      Re: openssh server remote access Semih Ozlem <semihozlemlinuxuser@gmail.com> - 2021-10-23 07:50 +0200
        Re: openssh server remote access Joe <joe@jretrading.com> - 2021-10-23 10:40 +0200
          Re: openssh server remote access Andrei POPESCU <andreimpopescu@gmail.com> - 2021-10-23 13:30 +0200
    Re: openssh server remote access Semih Ozlem <semihozlemlinuxuser@gmail.com> - 2021-10-21 23:10 +0200
      Re: openssh server remote access Greg Wooledge <greg@wooledge.org> - 2021-10-21 23:40 +0200
        Re: openssh server remote access Semih Ozlem <semihozlemlinuxuser@gmail.com> - 2021-10-22 01:00 +0200
          Re: openssh server remote access David <bouncingcats@gmail.com> - 2021-10-22 01:10 +0200
            Re: openssh server remote access "James B" <portoteacher80@fastmail.com> - 2021-10-22 01:20 +0200
              Re: openssh server remote access "James B" <portoteacher80@fastmail.com> - 2021-10-22 01:30 +0200
          Re: openssh server remote access Andrei POPESCU <andreimpopescu@gmail.com> - 2021-10-22 13:00 +0200
            Re: openssh server remote access Eric S Fraga <e.fraga@ucl.ac.uk> - 2021-10-22 13:10 +0200
              Re: openssh server remote access David Wright <deblis@lionunicorn.co.uk> - 2021-10-22 16:50 +0200
                Re: openssh server remote access Eric S Fraga <e.fraga@ucl.ac.uk> - 2021-10-22 19:20 +0200

#241567 — Re: openssh server remote access

FromSemih Ozlem <semihozlemlinuxuser@gmail.com>
Date2021-10-21 22:50 +0200
SubjectRe: openssh server remote access
Message-ID<DaNaF-6Fb-1@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

I think it was something like "ssh: connect to host .... port 22:
Connection refused" It will take me a little while to get the same error
message again.

James B <portoteacher80@fastmail.com>, 21 Eki 2021 Per, 23:45 tarihinde
şunu yazdı:

> Hi Semih,
>
> Could you post the exact wording of the error message please?
>
> Best
>
> JB
>
> --
>   James B
>   portoteacher80@fastmail.com
>
>
>
> Em Qui, 21 Out ʼ21, às 21:41, Semih Ozlem escreveu:
>
> Hi everyone,
>
> I set up an openssh server and I am trying to access that machine remotely
> (not from the local network. but from another ip address). I get an error
> (something about port 22). What setting needs to be checked and what needs
> to be done on the machine that openssh server is running and on the router
> that machine is connected to, so that openssh server can be accessed
> remotely?
>
> Thank you
>
> Semih Ozlem
>
>
>

[toc] | [next] | [standalone]


#241570

FromJoe <joe@jretrading.com>
Date2021-10-21 23:10 +0200
Message-ID<DaNu1-71r-1@gated-at.bofh.it>
In reply to#241567
On Thu, 21 Oct 2021 23:48:38 +0300
Semih Ozlem <semihozlemlinuxuser@gmail.com> wrote:

> I think it was something like "ssh: connect to host .... port 22:
> Connection refused" It will take me a little while to get the same
> error message again.
> 
>

Ideally you need to do more than open the ssh port, particularly if you
intend to connect from the Internet. ssh is one of the most commonly
attacked services, for obvious reasons.

You need a tutorial on setting up ssh with keys, and disabling password
access. There are many such on the Net.


-- 
Joe

[toc] | [prev] | [next] | [standalone]


#241611

FromSemih Ozlem <semihozlemlinuxuser@gmail.com>
Date2021-10-23 07:50 +0200
Message-ID<Dbi4O-jg-5@gated-at.bofh.it>
In reply to#241570

[Multipart message — attachments visible in raw view] — view raw

Are there specific tutorials websites that you can recommend, how about
port forwarding. From where which sites in particular can I learn about
these topics?

Joe <joe@jretrading.com>, 22 Eki 2021 Cum, 00:08 tarihinde şunu yazdı:

> On Thu, 21 Oct 2021 23:48:38 +0300
> Semih Ozlem <semihozlemlinuxuser@gmail.com> wrote:
>
> > I think it was something like "ssh: connect to host .... port 22:
> > Connection refused" It will take me a little while to get the same
> > error message again.
> >
> >
>
> Ideally you need to do more than open the ssh port, particularly if you
> intend to connect from the Internet. ssh is one of the most commonly
> attacked services, for obvious reasons.
>
> You need a tutorial on setting up ssh with keys, and disabling password
> access. There are many such on the Net.
>
>
> --
> Joe
>
>

[toc] | [prev] | [next] | [standalone]


#241613

FromJoe <joe@jretrading.com>
Date2021-10-23 10:40 +0200
Message-ID<DbkJj-1WF-1@gated-at.bofh.it>
In reply to#241611
On Sat, 23 Oct 2021 08:42:09 +0300
Semih Ozlem <semihozlemlinuxuser@gmail.com> wrote:

> Are there specific tutorials websites that you can recommend, how
> about port forwarding. From where which sites in particular can I
> learn about these topics?

Here's a good practical guide:

https://www.digitalocean.com/community/tutorials/how-to-set-up-ssh-keys-2

This site generally isn't specific to Debian, but it has lots of useful
tutorials. The Arch Linux site is also good for documentation.

Here is the ultimate authority, but it may contain too much detail for
a beginner. These are the client and server configuration files, which
are commented, but there's more detail here:

https://www.ssh.com/academy/ssh/config
https://www.ssh.com/academy/ssh/sshd_config

Mostly the default configuration files are OK, you may want to change
the port number or disable passwords. Most of the insecure options are
already disabled.

> 
> Joe <joe@jretrading.com>, 22 Eki 2021 Cum, 00:08 tarihinde şunu yazdı:
> 
> > On Thu, 21 Oct 2021 23:48:38 +0300
> > Semih Ozlem <semihozlemlinuxuser@gmail.com> wrote:
> >  
> > > I think it was something like "ssh: connect to host .... port 22:
> > > Connection refused" It will take me a little while to get the same
> > > error message again.

The ssh protocol by default works on TCP port 22, but the sshd (server)
configuration file allows different ports to be specified. If you have
port 22 open to the Internet, you will get many firewall logs for
people trying brute-force password attacks, which tells you why you
should be using keys. Using a different port won't be any more secure,
but it will stop these logs.

Wherever you want to connect from must have a clear path to the ssh
port of your server. If you want to connect across the Internet, then
your Internet router must forward the ssh port to the server computer.
How to do this is specific to each model of router, but it's usually
easy to work out. It will ask for an incoming protocol (TCP) and port
number, the IP address of the destination computer in your network, and
sometimes a destination port. In the latter case, you can still use
port 22 on the server but accept something else entirely from over the
Net. If the ssh server computer has a firewall, then it must have the
relevant port opened, which again will be specific to the software you
use for the firewall.
 

[toc] | [prev] | [next] | [standalone]


#241618

FromAndrei POPESCU <andreimpopescu@gmail.com>
Date2021-10-23 13:30 +0200
Message-ID<DbnnP-3yx-1@gated-at.bofh.it>
In reply to#241613

[Multipart message — attachments visible in raw view] — view raw

On Sb, 23 oct 21, 09:33:44, Joe wrote:
> 
> The ssh protocol by default works on TCP port 22, but the sshd (server)
> configuration file allows different ports to be specified. If you have
> port 22 open to the Internet, you will get many firewall logs for
> people trying brute-force password attacks, which tells you why you
> should be using keys. Using a different port won't be any more secure,
> but it will stop these logs.

I've seen such brute-force attacks[1] also on different ports, they are
just much rarer.

The simple (temporary) solution for me was to reboot the router so it 
gets a different IP from the ISP. Long term I should probably look into 
something like fail2ban and/or port knocking.
 
> Wherever you want to connect from must have a clear path to the ssh
> port of your server. If you want to connect across the Internet, then
> your Internet router must forward the ssh port to the server computer.
> How to do this is specific to each model of router, but it's usually
> easy to work out. It will ask for an incoming protocol (TCP) and port
> number, the IP address of the destination computer in your network, and
> sometimes a destination port. In the latter case, you can still use
> port 22 on the server but accept something else entirely from over the
> Net.

My recommendation as well, as I prefer to run with defaults whenever 
possible. If already configuring a port forwarding in the router it's 
easy to use a different port on the public face of the router and keep 
the SSH server at its default.

It also makes local SSH connections much easier as it's not necessary to 
reconfigure each client for each host.

[1] The attacks didn't get past guessing an existing user name, even 
though one is a common English word and one is a Romanian given name :D

Kind regards,
Andrei
-- 
http://wiki.debian.org/FAQsFromDebianUser

[toc] | [prev] | [next] | [standalone]


#241571

FromSemih Ozlem <semihozlemlinuxuser@gmail.com>
Date2021-10-21 23:10 +0200
Message-ID<DaNu1-71r-3@gated-at.bofh.it>
In reply to#241567

[Multipart message — attachments visible in raw view] — view raw

Yes the error message is

ssh: connect to host (ip address of remote host) port 22: Connection refused



Semih Ozlem <semihozlemlinuxuser@gmail.com>, 21 Eki 2021 Per, 20:48
tarihinde şunu yazdı:

> I think it was something like "ssh: connect to host .... port 22:
> Connection refused" It will take me a little while to get the same error
> message again.
>
> James B <portoteacher80@fastmail.com>, 21 Eki 2021 Per, 23:45 tarihinde
> şunu yazdı:
>
>> Hi Semih,
>>
>> Could you post the exact wording of the error message please?
>>
>> Best
>>
>> JB
>>
>> --
>>   James B
>>   portoteacher80@fastmail.com
>>
>>
>>
>> Em Qui, 21 Out ʼ21, às 21:41, Semih Ozlem escreveu:
>>
>> Hi everyone,
>>
>> I set up an openssh server and I am trying to access that machine
>> remotely (not from the local network. but from another ip address). I get
>> an error (something about port 22). What setting needs to be checked and
>> what needs to be done on the machine that openssh server is running and on
>> the router that machine is connected to, so that openssh server can be
>> accessed remotely?
>>
>> Thank you
>>
>> Semih Ozlem
>>
>>
>>

[toc] | [prev] | [next] | [standalone]


#241572

FromGreg Wooledge <greg@wooledge.org>
Date2021-10-21 23:40 +0200
Message-ID<DaNX4-7bl-17@gated-at.bofh.it>
In reply to#241571
On Thu, Oct 21, 2021 at 09:07:02PM +0000, Semih Ozlem wrote:
> Yes the error message is
> 
> ssh: connect to host (ip address of remote host) port 22: Connection refused

This message means one of these things:

1) The sshd process is not running, or is not listening on the default port.

2) A firewall is preventing your connection.


You would normally check the first thing by using "ss" or "netstat" on
the server, and verifying that the process is indeed LISTEN-ing on the
expected interface(s) and port.  For example:

unicorn:~$ ss -ant | grep :22
LISTEN    0      128              0.0.0.0:22                     0.0.0.0:*
[...]

This tells me that something is listning on port 22 on all IPv4 interfaces.

If you don't see a line like this, then you need to investigate the ssh
service more deeply.  Perhaps start by running "journalctl -u ssh" to
read its logs.

If you *do* see a line like this, then you need to look at network-level
stuff, like firewalls, routers, and so on.

[toc] | [prev] | [next] | [standalone]


#241574

FromSemih Ozlem <semihozlemlinuxuser@gmail.com>
Date2021-10-22 01:00 +0200
Message-ID<DaPct-7Qq-1@gated-at.bofh.it>
In reply to#241572

[Multipart message — attachments visible in raw view] — view raw

I am unable to access my modem settings page when writing 192.168.1.100 to
check if there is a firewall.

Below is the web page that I get


Unable to connect

Firefox can’t establish a connection to the server at 192.168.1.100.

    The site could be temporarily unavailable or too busy. Try again in a
few moments.
    If you are unable to load any pages, check your computer’s network
connection.
    If your computer or network is protected by a firewall or proxy, make
sure that Firefox is permitted to access the Web.

Any ideas?

Greg Wooledge <greg@wooledge.org>, 21 Eki 2021 Per, 21:32 tarihinde şunu
yazdı:

> On Thu, Oct 21, 2021 at 09:07:02PM +0000, Semih Ozlem wrote:
> > Yes the error message is
> >
> > ssh: connect to host (ip address of remote host) port 22: Connection
> refused
>
> This message means one of these things:
>
> 1) The sshd process is not running, or is not listening on the default
> port.
>
> 2) A firewall is preventing your connection.
>
>
> You would normally check the first thing by using "ss" or "netstat" on
> the server, and verifying that the process is indeed LISTEN-ing on the
> expected interface(s) and port.  For example:
>
> unicorn:~$ ss -ant | grep :22
> LISTEN    0      128              0.0.0.0:22                     0.0.0.0:*
> [...]
>
> This tells me that something is listning on port 22 on all IPv4 interfaces.
>
> If you don't see a line like this, then you need to investigate the ssh
> service more deeply.  Perhaps start by running "journalctl -u ssh" to
> read its logs.
>
> If you *do* see a line like this, then you need to look at network-level
> stuff, like firewalls, routers, and so on.
>
>

[toc] | [prev] | [next] | [standalone]


#241575

FromDavid <bouncingcats@gmail.com>
Date2021-10-22 01:10 +0200
Message-ID<DaPm9-88S-1@gated-at.bofh.it>
In reply to#241574
On Fri, 22 Oct 2021 at 09:53, Semih Ozlem <semihozlemlinuxuser@gmail.com> wrote:

> From:Semih Ozlem <semihozlemlinuxuser@gmail.com>
> To:Debian Users <debian-user@lists.debian.org>, ubuntu-users@lists.ubuntu.com

Please, do not send individual messages to more than one
mailing list.

It is rather unfriendly to everyone else that reads each list, because
we do not see any conversation that occurs on the other mailing list.

Please confine any conversations that you have, on any mailing list,
entirely to that one mailing list. Sure, you can ask the same question
on multiple mailing lists at the same time, but please keep them
as separate conversations.

[toc] | [prev] | [next] | [standalone]


#241576

From"James B" <portoteacher80@fastmail.com>
Date2021-10-22 01:20 +0200
Message-ID<DaPvQ-8c7-5@gated-at.bofh.it>
In reply to#241575
Hi Semih,

In my opinion, I would go back to basics first.You may have installed openssh but it doesn't necessarily run by default (for reasons that will make sense when you look at it further).Do you know how to start systemd services? It looks to me like your ssh server isnt' running.So, run (with sudo privileges or root and presuming you're on a normal variant of Debian and not one with an alternative init system such as SysV)

1) systemctl status ssh

Post the result please

JB

-- 
  James B
  portoteacher80@fastmail.com

Em Sex, 22 Out ʼ21, às 00:05, David escreveu:
> On Fri, 22 Oct 2021 at 09:53, Semih Ozlem <semihozlemlinuxuser@gmail.com> wrote:
>
>> From:Semih Ozlem <semihozlemlinuxuser@gmail.com>
>> To:Debian Users <debian-user@lists.debian.org>, ubuntu-users@lists.ubuntu.com
>
> Please, do not send individual messages to more than one
> mailing list.
>
> It is rather unfriendly to everyone else that reads each list, because
> we do not see any conversation that occurs on the other mailing list.
>
> Please confine any conversations that you have, on any mailing list,
> entirely to that one mailing list. Sure, you can ask the same question
> on multiple mailing lists at the same time, but please keep them
> as separate conversations.

[toc] | [prev] | [next] | [standalone]


#241577

From"James B" <portoteacher80@fastmail.com>
Date2021-10-22 01:30 +0200
Message-ID<DaPFv-8eS-1@gated-at.bofh.it>
In reply to#241576
That's 'systemctl status ssh' without the 1) of course.I meant to put more steps but decided not to

-- 
  James B
  portoteacher80@fastmail.com

Em Sex, 22 Out ʼ21, às 00:18, James B escreveu:
> Hi Semih,
>
> In my opinion, I would go back to basics first.You may have installed 
> openssh but it doesn't necessarily run by default (for reasons that 
> will make sense when you look at it further).Do you know how to start 
> systemd services? It looks to me like your ssh server isnt' running.So, 
> run (with sudo privileges or root and presuming you're on a normal 
> variant of Debian and not one with an alternative init system such as 
> SysV)
>
> 1) systemctl status ssh
>
> Post the result please
>
> JB
>
> -- 
>   James B
>   portoteacher80@fastmail.com
>
> Em Sex, 22 Out ʼ21, às 00:05, David escreveu:
>> On Fri, 22 Oct 2021 at 09:53, Semih Ozlem <semihozlemlinuxuser@gmail.com> wrote:
>>
>>> From:Semih Ozlem <semihozlemlinuxuser@gmail.com>
>>> To:Debian Users <debian-user@lists.debian.org>, ubuntu-users@lists.ubuntu.com
>>
>> Please, do not send individual messages to more than one
>> mailing list.
>>
>> It is rather unfriendly to everyone else that reads each list, because
>> we do not see any conversation that occurs on the other mailing list.
>>
>> Please confine any conversations that you have, on any mailing list,
>> entirely to that one mailing list. Sure, you can ask the same question
>> on multiple mailing lists at the same time, but please keep them
>> as separate conversations.

[toc] | [prev] | [next] | [standalone]


#241589

FromAndrei POPESCU <andreimpopescu@gmail.com>
Date2021-10-22 13:00 +0200
Message-ID<Db0rg-6n1-17@gated-at.bofh.it>
In reply to#241574

[Multipart message — attachments visible in raw view] — view raw

On Jo, 21 oct 21, 22:52:37, Semih Ozlem wrote:
> I am unable to access my modem settings page when writing 192.168.1.100 to
> check if there is a firewall.

Are you sure this is the correct address? How did you establish that?

Typically modems and home routers use the .1 address for themselves.

Even if the firewall is disabled on the modem (it shouldn't be, and you 
should probably leave it enabled), systems connecting to the internet 
via the modem are usually inaccessible from the internet.

To connect to them from the internet you need a "port forwarding".

https://en.wikipedia.org/wiki/Port_forwarding

Kind regards,
Andrei
-- 
http://wiki.debian.org/FAQsFromDebianUser

[toc] | [prev] | [next] | [standalone]


#241590

FromEric S Fraga <e.fraga@ucl.ac.uk>
Date2021-10-22 13:10 +0200
Message-ID<Db0AW-6FR-1@gated-at.bofh.it>
In reply to#241589
On Friday, 22 Oct 2021 at 13:40, Andrei POPESCU wrote:
> Typically modems and home routers use the .1 address for themselves.

Interesting.  My last 2 routers have had *.254 (!) and *.100 as their
address. 

-- 
Eric S Fraga via Emacs 28.0.60 & org 9.5 on Debian 11.1

[toc] | [prev] | [next] | [standalone]


#241598

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2021-10-22 16:50 +0200
Message-ID<Db41Q-6s-13@gated-at.bofh.it>
In reply to#241590
On Fri 22 Oct 2021 at 11:59:40 (+0100), Eric S Fraga wrote:
> On Friday, 22 Oct 2021 at 13:40, Andrei POPESCU wrote:
> > Typically modems and home routers use the .1 address for themselves.
> 
> Interesting.  My last 2 routers have had *.254 (!)

I'm guessing it was a BT Home Hub. It's idiosyncratic, but setting
itself to the highest address is as logical as the lowest, is it not.

> and *.100 as their address. 

One might suspect that 100 lies at the lower boundary of its DHCP
range, leaving 99 static addresses free. But no guess at a product.

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#241606

FromEric S Fraga <e.fraga@ucl.ac.uk>
Date2021-10-22 19:20 +0200
Message-ID<Db6mZ-1DN-3@gated-at.bofh.it>
In reply to#241598
On Friday, 22 Oct 2021 at 09:46, David Wright wrote:
> I'm guessing it was a BT Home Hub. 

EE *before* bought by BT but maybe same supplier even then.

> One might suspect that 100 lies at the lower boundary of its DHCP
> range, leaving 99 static addresses free. But no guess at a product.

I cannot remember any longer which one supplied this one.  Might have
been Tiscali?

And, yes, leaving 99 static addresses free might be a reason.


-- 
Eric S Fraga via Emacs 28.0.60 & org 9.5 on Debian 11.1

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web