Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Spurious tcp reset packets?

4 views
Skip to first unread message

Bruno Wolff III

unread,
Aug 24, 2008, 6:04:13 PM8/24/08
to
I have been seeing spurious tcp resets for ssh connections for the last
several weeks. I haven't tracked down the source yet. I was wondering
if any one else was seeing any? I think my LAN router is a suspect for
them but if other people were seeing them I might suspect that there is
something on their network and I would make getting the EFF's tool a try
a higher priority.

qay...@gmail.com

unread,
Aug 25, 2008, 4:30:13 AM8/25/08
to

I haven't been having any problems SSHing to or from my server on a
Speakeasy DSL line.

Scott Hemphill

unread,
Aug 25, 2008, 8:56:45 AM8/25/08
to

I am no longer a Speakeasy customer, but post this in the slight
chance it may be of some use:

Are the resets truly spurious, or do they look like timeouts? If they
are timeouts, then you can work around them with a suitable
ClientAliveInterval in /etc/ssh/sshd_config on the server end.

Good luck!

Scott
--
Scott Hemphill hemp...@alumni.caltech.edu
"This isn't flying. This is falling, with style." -- Buzz Lightyear

Bruno Wolff III

unread,
Aug 25, 2008, 11:09:03 AM8/25/08
to
On 2008-08-25, Scott Hemphill <hemp...@hemphills.net> wrote:
> Bruno Wolff III <br...@wolff.to> writes:
>
> Are the resets truly spurious, or do they look like timeouts? If they
> are timeouts, then you can work around them with a suitable
> ClientAliveInterval in /etc/ssh/sshd_config on the server end.

No they aren't timeouts. Blocking them seems to help. I think the most
likely cause is an overloaded firewall either on the router or the server.
I think the connection tracking might be getting overloaded by all of the
spam connections. The server is falling back to using syn cookies and the
problems with connections seem to correlate with when this is happening.
I have some ideas on how to test if the firewall on the server is having
a problem and I think I will start there as that is the most likely cause.

0 new messages