SSH连接报错kex_exchange_identification: read: Connection reset by peer的排查求助
SSH连接报错kex_exchange_identification: read: Connection reset by peer的排查求助
我已经花了好几天时间解决 kex_exchange_identification: read: connection reset by peer 这个SSH连接错误,但一直没进展。我试过重启路由器、关闭Linux防火墙,结果还是弹出同样的错误。ping目标SSH服务器是能通的,但奇怪的是服务器根本不会提示我输入客户端密码,这让我摸不着头脑。
下面是我在客户端和服务器上执行的命令及对应输出,麻烦大佬帮忙看看:
客户端侧操作及输出
1. 带调试日志的SSH连接命令
~ $:ssh -vvv ghegheg@100.96.180.251
输出内容:
OpenSSH_8.9p1 Ubuntu-3ubuntu0.1, OpenSSL 3.0.2 15 Mar 2022 debug1: Reading configuration data /etc/ssh/ssh_config debug1: /etc/ssh/ssh_config line 19: include /etc/ssh/ssh_config.d/*.conf matched no files debug1: /etc/ssh/ssh_config line 21: Applying options for * debug2: resolve_canonicalize: hostname 100.96.180.251 is address debug3: expanded UserKnownHostsFile '~/.ssh/known_hosts' -> '/home/ghegheg/.ssh/known_hosts' debug3: expanded UserKnownHostsFile '~/.ssh/known_hosts2' -> '/home/ghegheg/.ssh/known_hosts2' debug3: ssh_connect_direct: entering debug1: Connecting to 100.96.180.251 [100.96.180.251] port 22. debug3: set_sock_tos: set socket 3 IP_TOS 0x10 debug1: Connection established. debug1: identity file /home/ghegheg/.ssh/id_rsa type -1 debug1: identity file /home/ghegheg/.ssh/id_rsa-cert type -1 debug1: identity file /home/ghegheg/.ssh/id_ecdsa type -1 debug1: identity file /home/ghegheg/.ssh/id_ecdsa-cert type -1 debug1: identity file /home/ghegheg/.ssh/id_ecdsa_sk type -1 debug1: identity file /home/ghegheg/.ssh/id_ecdsa_sk-cert type -1 debug1: identity file /home/ghegheg/.ssh/id_ed25519 type -1 debug1: identity file /home/ghegheg/.ssh/id_ed25519-cert type -1 debug1: identity file /home/ghegheg/.ssh/id_ed25519_sk type -1 debug1: identity file /home/ghegheg/.ssh/id_ed25519_sk-cert type -1 debug1: identity file /home/ghegheg/.ssh/id_xmss type -1 debug1: identity file /home/ghegheg/.ssh/id_xmss-cert type -1 debug1: identity file /home/ghegheg/.ssh/id_dsa type -1 debug1: identity file /home/ghegheg/.ssh/id_dsa-cert type -1 debug1: Local version string SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.1 kex_exchange_identification: read: Connection reset by peer Connection reset by 100.96.180.251 port 22
2. 客户端SSH配置(/etc/ssh/ssh_config)
~ $:sudo vim /etc/ssh/ssh_config
配置内容:
# HostbasedAuthentication no # GSSAPIAuthentication no # GSSAPIDelegateCredentials no # GSSAPIKeyExchange no # GSSAPITrustDNS no # BatchMode no # CheckHostIP yes # AddressFamily any # ConnectTimeout 0 # StrictHostKeyChecking ask # IdentityFile ~/.ssh/id_rsa # IdentityFile ~/.ssh/id_dsa # IdentityFile ~/.ssh/id_ecdsa # IdentityFile ~/.ssh/id_ed25519 # Port 22 # Ciphers aes128-ctr,aes192-ctr,aes256-ctr,aes128-cbc,3des-cbc # MACs hmac-md5,hmac-sha1,umac-64@openssh.com # EscapeChar ~ # Tunnel no # TunnelDevice any:any # PermitLocalCommand no # VisualHostKey no # ProxyCommand ssh -q -W %h:%p gateway.example.com # RekeyLimit 1G 1h # UserKnownHostsFile ~/.ssh/known_hosts.d/%k SendEnv LANG LC_* HashKnownHosts yes GSSAPIAuthentication yes
服务器侧操作及输出
1. SSH服务状态(systemctl status sshd)
$:sudo systemctl status sshd
输出内容:
ssh.service - OpenBSD Secure Shell server Loaded: loaded (/lib/systemd/system/ssh.service; enabled; vendor preset: enabled) Active: active (running) since Wed 2023-03-29 13:06:24 EEST; 2h 56min ago Docs: man:sshd(8) man:sshd_config(5) Main PID: 946 (sshd) Tasks: 1 (limit: 19006) Memory: 3.8M CPU: 57ms CGroup: /system.slice/ssh.service └─946 "sshd: /usr/sbin/sshd -D [listener] 0 of 10-100 startups" mar 29 13:06:24 ghegheg-Z490M-GAMING-X systemd[1]: Starting OpenBSD Secure Shell server... mar 29 13:06:24 ghegheg-Z490M-GAMING-X sshd[946]: Server listening on 0.0.0.0 port 22. mar 29 13:06:24 ghegheg-Z490M-GAMING-X sshd[946]: Server listening on :: port 22. mar 29 13:06:24 ghegheg-Z490M-GAMING-X systemd[1]: Started OpenBSD Secure Shell server. mar 29 14:47:14 ghegheg-Z490M-GAMING-X sshd[24517]: fatal: Timeout before authentication for 5.14.134.233 port 53414 mar 29 15:37:21 ghegheg-Z490M-GAMING-X sshd[25471]: fatal: Timeout before authentication for 5.14.134.233 port 41608 mar 29 15:57:43 ghegheg-Z490M-GAMING-X sshd[26442]: fatal: Timeout before authentication for 5.14.134.233 port 54108
2. 服务器SSH配置(/etc/ssh/sshd_config)
$:vim /etc/ssh/sshd_config
配置内容:
# This is the sshd server system-wide configuration file. See # sshd_config(5) for more information. # This sshd was compiled with PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/usr/games # The strategy used for options in the default sshd_config shipped with # OpenSSH is to specify options with their default value where # possible, but leave them commented. Uncommented options override the # default value. Include /etc/ssh/sshd_config.d/*.conf #Port 22 #AddressFamily any #ListenAddress 0.0.0.0 #ListenAddress :: #HostKey /etc/ssh/ssh_host_rsa_key #HostKey /etc/ssh/ssh_host_ecdsa_key #HostKey /etc/ssh/ssh_host_ed25519_key # Ciphers and keying #RekeyLimit default none # Logging #SyslogFacility AUTH #LogLevel INFO # Authentication: #LoginGraceTime 2m #PermitRootLogin prohibit-password #StrictModes yes #MaxAuthTries 6 #MaxSessions 10
3. 服务器hosts.allow配置
$:vim /etc/hosts.allow
配置内容:
# /etc/hosts.allow: list of hosts that are allowed to access the system. # See the manual pages hosts_access(5) and hosts_options(5). # # Example: ALL: LOCAL @some_netgroup # ALL: .foobar.edu EXCEPT terminalserver.foobar.edu # # If you're going to protect the portmapper use the name "rpcbind" for the # daemon name. See rpcbind(8) and rpc.mountd(8) for further information. #
4. 服务器hosts.deny配置
$:vim /etc/hosts.deny
配置内容:
# /etc/hosts.deny: list of hosts that are _not_ allowed to access the system. # See the manual pages hosts_access(5) and hosts_options(5). # # Example: ALL: some.host.name, .some.domain # ALL EXCEPT in.fingerd: other.host.name, .other.domain # # If you're going to protect the portmapper use the name "rpcbind" for the # daemon name. See rpcbind(8) and rpc.mountd(8) for further information. # # The PARANOID wildcard matches any host whose name does not match its # address. # # You may wish to enable this to ensure any programs that don't # validate looked up hostnames still leave understandable logs. In past # versions of Debian this has been the default. # ALL: PARANOID
我现在完全不知道该从哪里下手了。另外我注意到服务器日志里出现了几条 fatal: Timeout before authentication for 5.14.134.233 port XXXX 的记录,这些端口都不是SSH的22端口,这会不会和我的问题有关?有没有经验丰富的大佬能给我点排查方向,帮我解决这个头疼的问题?
备注:内容来源于stack exchange,提问作者Mitu Gabriel
相关产品推荐
相关产品推荐

