<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Not able to ssh to outside world (WAN)]]></title><description><![CDATA[<p dir="auto">Dear All,<br />
I had did nothing on my pfsense firewall and suddenly i cannot connect my company jumphost using ssh. May I know how to diagnose it? Where to see the log according to ssh connection? Thanks.</p>
]]></description><link>https://forum.netgate.com/topic/165089/not-able-to-ssh-to-outside-world-wan</link><generator>RSS for Node</generator><lastBuildDate>Thu, 12 Mar 2026 14:27:32 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/165089.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 13 Jul 2021 09:21:30 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Not able to ssh to outside world (WAN) on Wed, 14 Jul 2021 14:20:45 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/peter_apiit">@<bdi>peter_apiit</bdi></a> said in <a href="/post/992008">Not able to ssh to outside world (WAN)</a>:</p>
<blockquote>
<p dir="auto">connect my company jumphost using ssh</p>
</blockquote>
<p dir="auto">Can you change the settings of this ssh access ?<br />
Change the '22' port to '2222' and you'll be good.</p>
]]></description><link>https://forum.netgate.com/post/992229</link><guid isPermaLink="true">https://forum.netgate.com/post/992229</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Wed, 14 Jul 2021 14:20:45 GMT</pubDate></item><item><title><![CDATA[Reply to Not able to ssh to outside world (WAN) on Wed, 14 Jul 2021 12:12:38 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>gertjan</bdi></a> said in <a href="/post/992190">Not able to ssh to outside world (WAN)</a>:</p>
<blockquote>
<p dir="auto">what about terminating your relation with this ISP.</p>
</blockquote>
<p dir="auto">I would agree with this.. While I get some isp should prob block some outbound access.. SMTP is one of these that comes to mind that many an ISP might block outbound on a residential connection.  SMB also serves now real purpose being sent over the public internet 137-139,445 for example.</p>
<p dir="auto">But ssh - yeah that could be problematic.. But I could see the logic behind maybe blocking that for your typical residential account.. I would be really pissed if my isp did that.. that is for sure..</p>
]]></description><link>https://forum.netgate.com/post/992194</link><guid isPermaLink="true">https://forum.netgate.com/post/992194</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Wed, 14 Jul 2021 12:12:38 GMT</pubDate></item><item><title><![CDATA[Reply to Not able to ssh to outside world (WAN) on Wed, 14 Jul 2021 12:08:16 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/peter_apiit">@<bdi>peter_apiit</bdi></a></p>
<p dir="auto">It blocks destination port 22 TCP ?</p>
<p dir="auto"><img src="https://forum.netgate.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f44e.png?v=d0a5ddc94ac" class="not-responsive emoji emoji-android emoji---1" style="height:23px;width:auto;vertical-align:middle" title=":-1:" alt="👎" /></p>
<p dir="auto">Instead of investing in a VPN, what about terminating your relation with this ISP.</p>
<p dir="auto">And just for my own curiosity : what country I/ ISP ?</p>
]]></description><link>https://forum.netgate.com/post/992190</link><guid isPermaLink="true">https://forum.netgate.com/post/992190</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Wed, 14 Jul 2021 12:08:16 GMT</pubDate></item><item><title><![CDATA[Reply to Not able to ssh to outside world (WAN) on Wed, 14 Jul 2021 11:17:23 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/johnpoz">@<bdi>johnpoz</bdi></a> I solve it by initiate a VPN connection since my ISP block me.</p>
]]></description><link>https://forum.netgate.com/post/992180</link><guid isPermaLink="true">https://forum.netgate.com/post/992180</guid><dc:creator><![CDATA[Peter_APIIT]]></dc:creator><pubDate>Wed, 14 Jul 2021 11:17:23 GMT</pubDate></item><item><title><![CDATA[Reply to Not able to ssh to outside world (WAN) on Wed, 14 Jul 2021 10:52:25 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/peter_apiit">@<bdi>peter_apiit</bdi></a> and what was the output of ssh?  What did it tell you??  Did it say host not found?</p>
]]></description><link>https://forum.netgate.com/post/992176</link><guid isPermaLink="true">https://forum.netgate.com/post/992176</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Wed, 14 Jul 2021 10:52:25 GMT</pubDate></item><item><title><![CDATA[Reply to Not able to ssh to outside world (WAN) on Wed, 14 Jul 2021 10:43:33 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/johnpoz">@<bdi>johnpoz</bdi></a> I tried initiate command ssh -v to find out the ip address of the ssh server but i don't see any logged by this ip. Any other thought?</p>
]]></description><link>https://forum.netgate.com/post/992171</link><guid isPermaLink="true">https://forum.netgate.com/post/992171</guid><dc:creator><![CDATA[Peter_APIIT]]></dc:creator><pubDate>Wed, 14 Jul 2021 10:43:33 GMT</pubDate></item><item><title><![CDATA[Reply to Not able to ssh to outside world (WAN) on Wed, 14 Jul 2021 08:33:39 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/peter_apiit">@<bdi>peter_apiit</bdi></a> said in <a href="/post/992126">Not able to ssh to outside world (WAN)</a>:</p>
<blockquote>
<p dir="auto">find the ip been blocked by the firewall.</p>
</blockquote>
<p dir="auto">Who says the firewall is blocking anything?  Unless you disabled logging - anything blocked would be logged.</p>
]]></description><link>https://forum.netgate.com/post/992138</link><guid isPermaLink="true">https://forum.netgate.com/post/992138</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Wed, 14 Jul 2021 08:33:39 GMT</pubDate></item><item><title><![CDATA[Reply to Not able to ssh to outside world (WAN) on Wed, 14 Jul 2021 05:52:18 GMT]]></title><description><![CDATA[<p dir="auto">Still not able to diagnose the root cause. I try with ssh -v but cannot find the ip been blocked by the firewall. I stop the Snort, Pf-blocker but still not able to find the root cause.</p>
]]></description><link>https://forum.netgate.com/post/992126</link><guid isPermaLink="true">https://forum.netgate.com/post/992126</guid><dc:creator><![CDATA[Peter_APIIT]]></dc:creator><pubDate>Wed, 14 Jul 2021 05:52:18 GMT</pubDate></item><item><title><![CDATA[Reply to Not able to ssh to outside world (WAN) on Tue, 13 Jul 2021 10:27:24 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/peter_apiit">@<bdi>peter_apiit</bdi></a></p>
<p dir="auto">Connect to some server using TCP, port 80, or port 443, or port 110, or 445, or port 143, etc uses :<br />
The IP address, and a port number.</p>
<p dir="auto">You could use a host name in FQDN format, like sshaccess.myserver.tld. In that case, check if "sshaccess.myserver.tld" resolves to the correct IP.</p>
<p dir="auto">(destination) IP's, hostnames (using DNSBL) can be - this is the outgoing traffic - blocked by pfSense.<br />
But why would you block yourself ?</p>
<p dir="auto">The SSH access is, like the one pfSense uses, often protected. Miss spell your password 10 x and you'll be locked out for some time - ask the admin for how long.<br />
If you suspect this happens, use another WAN IP, and if you have access to SSH account now, you know the "SSH sever" blocked your initial WAN IP.</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/peter_apiit">@<bdi>peter_apiit</bdi></a> said in <a href="/post/992008">Not able to ssh to outside world (WAN)</a>:</p>
<blockquote>
<p dir="auto">Where to see the log</p>
</blockquote>
<p dir="auto">The firewall logs (of course) !?!<br />
So did you put a firewall rule on the LAN interface and you don't know if it will block yourself, when you're are using a legit connection ?<br />
I guess not.</p>
]]></description><link>https://forum.netgate.com/post/992010</link><guid isPermaLink="true">https://forum.netgate.com/post/992010</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Tue, 13 Jul 2021 10:27:24 GMT</pubDate></item><item><title><![CDATA[Reply to Not able to ssh to outside world (WAN) on Tue, 13 Jul 2021 10:17:03 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/peter_apiit">@<bdi>peter_apiit</bdi></a> said in <a href="/post/992008">Not able to ssh to outside world (WAN)</a>:</p>
<blockquote>
<p dir="auto">Where to see the log according to ssh connection? Thanks.</p>
</blockquote>
<p dir="auto">In your ssh client would be the first place.. Does it show the connection even starting, ie able to even connect to the host?</p>
<p dir="auto">As to logs on pfsense - out of the box it does not log allowed stuff, only blocked.</p>
<p dir="auto">You can look in your state table to see if a state was created.  You could sniff on your wan and validate the ssh tcp syn when out, and did you get an answer?</p>
<p dir="auto">If you are having problems connecting to some ssh server, the best place to start looking is the ssh client itself - connect with -v and will show you info related to the process..</p>
<p dir="auto">Here is starting the connection for example</p>
<pre><code>C:\&gt;ssh -v 192.168.3.10
OpenSSH_8.5p1, OpenSSL 1.1.1f  31 Mar 2020
debug1: Connecting to 192.168.3.10 [192.168.3.10] port 22.
debug1: Connection established.
</code></pre>
<p dir="auto">then you will get lots of info about that connection starting..</p>
<pre><code>debug1: Local version string SSH-2.0-OpenSSH_8.5
debug1: Remote protocol version 2.0, remote software version OpenSSH_7.9p1 Raspbian-10+deb10u2+rpt1
debug1: compat_banner: match: OpenSSH_7.9p1 Raspbian-10+deb10u2+rpt1 pat OpenSSH* compat 0x04000000

debug1: SSH2_MSG_KEXINIT sent
debug1: SSH2_MSG_KEXINIT received
debug1: kex: algorithm: curve25519-sha256
debug1: kex: host key algorithm: ecdsa-sha2-nistp256
debug1: kex: server-&gt;client cipher: chacha20-poly1305@openssh.com MAC: &lt;implicit&gt; compression: none
debug1: kex: client-&gt;server cipher: chacha20-poly1305@openssh.com MAC: &lt;implicit&gt; compression: none
debug1: expecting SSH2_MSG_KEX_ECDH_REPLY
debug1: SSH2_MSG_KEX_ECDH_REPLY received
</code></pre>
<p dir="auto">etc. etc..</p>
<p dir="auto">But if you can not even get the first connection.. Say for example something like this</p>
<pre><code>C:\&gt;ssh -v 192.168.2.50
OpenSSH_8.5p1, OpenSSL 1.1.1f  31 Mar 2020
debug1: Connecting to 192.168.2.50 [192.168.2.50] port 22.
debug1: connect to address 192.168.2.50 port 22: Connection refused
ssh: connect to host 192.168.2.50 port 22: Connection refused
</code></pre>
<p dir="auto">Then you would need to look to pfsense logs/states/sniff to see if traffic went where it was suppose to go, did you get back a syn,ack, etc..</p>
]]></description><link>https://forum.netgate.com/post/992009</link><guid isPermaLink="true">https://forum.netgate.com/post/992009</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Tue, 13 Jul 2021 10:17:03 GMT</pubDate></item></channel></rss>