• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

2.3 SSH disable kills traffic

2.3-RC Snapshot Feedback and Issues - ARCHIVED
3
7
1.8k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • R
    relias
    last edited by Mar 30, 2016, 6:36 PM

    If we disable remote SSH it we no longer have internet access. We have not been able to do further troubleshooting as we discovered this in production but have confirmed the behavior.

    1 Reply Last reply Reply Quote 0
    • C
      cmb
      last edited by Mar 30, 2016, 7:13 PM

      What do you mean "disable remote SSH"?

      Just turning off the SSH service does nothing but stop sshd. It has no impact on whether or not traffic goes through the system.

      1 Reply Last reply Reply Quote 0
      • R
        relias
        last edited by Mar 30, 2016, 8:55 PM

        I understand, but that's the result of changing the following in the webconfigurator:

        Enable Secure Shell

        1 Reply Last reply Reply Quote 0
        • M
          macboy6
          last edited by Mar 30, 2016, 10:09 PM

          I just disabled Secure Shell Daemon in Status–>Services.  No issue accessing internet at all.

          Currently on 2.3.b.20160330.1215_1

          1 Reply Last reply Reply Quote 0
          • C
            cmb
            last edited by Mar 30, 2016, 11:29 PM

            That definitely doesn't stop traffic from passing. I can't think of anything it could impact that would have any effect on traffic through the system. SSH has no relation to anything that passes traffic.

            Need something more specific. What's a traceroute from LAN to something on the Internet look like when it's not working? DNS lookups work? Ping out to Internet from Diag>Ping work?

            1 Reply Last reply Reply Quote 0
            • R
              relias
              last edited by Mar 31, 2016, 8:24 PM

              I can run those requested test this weekend during non operations hours as this firewall is currently in production. The upgrade was suggested and performed by support. I recently read that store hardware will run a separate branch of the software once released, hopefully the switch will be seamless.

              Aside from what you mentioned above, is there any other test I should perform?

              1 Reply Last reply Reply Quote 0
              • C
                cmb
                last edited by Mar 31, 2016, 9:34 PM

                Actually I was the one who upgraded your system. Didn't realize who you were until looking at your profile. That makes even less sense knowing what's on your system.

                I'd like to work with you on testing this over the weekend. I'll PM you to see if we can arrange.

                1 Reply Last reply Reply Quote 0
                1 out of 7
                • First post
                  1/7
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.