在Windows的WSL环境中SSH连接Vagrant虚拟机失败求助
我现在遇到个头疼的问题:Windows 10主机上跑着Vagrant虚拟机,默认端口转发是把虚拟机的22端口映射到Windows主机的2222端口。我想从同一台机器的WSL里SSH连过去,试了localhost、127.0.0.1、0.0.0.0,还有WSL里/etc/resolv.conf里的IP(172.31.224.1),用命令ssh {username}@{IP} -p 2222尝试连接,结果既没被拒绝,就一直卡在那直到超时。我已经在Windows上添了允许2222端口进出的防火墙规则,但还是没用,而且从WSL ping那个/etc/resolv.conf里的IP也没响应。
附上我的配置文件:
/etc/ssh/sshd_config
# $OpenBSD: sshd_config,v 1.103 2018/04/09 20:41:22 tj Exp $ # This is the sshd server system-wide configuration file. See # sshd_config(5) for more information. # This sshd was compiled with PATH=/usr/bin:/bin:/usr/sbin:/sbin # The strategy used for options in the default sshd_config shipped with # OpenSSH is to specify options with their default value where # possible, but leave them commented. Uncommented options override the # default value. Include /etc/ssh/sshd_config.d/*.conf #Port 22 #AddressFamily any #ListenAddress 0.0.0.0 #ListenAddress :: #HostKey /etc/ssh/ssh_host_rsa_key #HostKey /etc/ssh/ssh_host_ecdsa_key #HostKey /etc/ssh/ssh_host_ed25519_key # Ciphers and keying #RekeyLimit default none # Logging #SyslogFacility AUTH #LogLevel INFO # Authentication: #LoginGraceTime 2m #PermitRootLogin prohibit-password #StrictModes yes #MaxAuthTries 6 #MaxSessions 10 #PubkeyAuthentication yes # Expect .ssh/authorized_keys2 to be disregarded by default in future. #AuthorizedKeysFile .ssh/authorized_keys .ssh/authorized_keys2 #AuthorizedPrincipalsFile none #AuthorizedKeysCommand none #AuthorizedKeysCommandUser nobody # For this to work you will also need host keys in /etc/ssh/ssh_known_hosts #HostbasedAuthentication no # Change to yes if you don't trust ~/.ssh/known_hosts for # HostbasedAuthentication #IgnoreUserKnownHosts no # Don't read the user's ~/.rhosts and ~/.shosts files #IgnoreRhosts yes # To disable tunneled clear text passwords, change to no here! PasswordAuthentication no #PermitEmptyPasswords no # Change to yes to enable challenge-response passwords (beware issues with # some PAM modules and threads) ChallengeResponseAuthentication no # Kerberos options #KerberosAuthentication no #KerberosOrLocalPasswd yes #KerberosTicketCleanup yes #KerberosGetAFSToken no # GSSAPI options #GSSAPIAuthentication no #GSSAPICleanupCredentials yes #GSSAPIStrictAcceptorCheck yes #GSSAPIKeyExchange no # Set this to 'yes' to enable PAM authentication, account processing, # and session processing. If this is enabled, PAM authentication will # be allowed through the ChallengeResponseAuthentication and # PasswordAuthentication. Depending on your PAM configuration, # PAM authentication via ChallengeResponseAuthentication may bypass # the setting of "PermitRootLogin without-password". # If you just want the PAM account and session checks to run without # PAM authentication, then enable this but set PasswordAuthentication # and ChallengeResponseAuthentication to 'no'. UsePAM yes #AllowAgentForwarding yes #AllowTcpForwarding yes #GatewayPorts no X11Forwarding yes #X11DisplayOffset 10 #X11UseLocalhost yes #PermitTTY yes PrintMotd no #PrintLastLog yes #TCPKeepAlive yes #PermitUserEnvironment no #Compression delayed #ClientAliveInterval 0 #ClientAliveCountMax 3 #UseDNS no #PidFile /var/run/sshd.pid #MaxStartups 10:30:100 #PermitTunnel no #ChrootDirectory none #VersionAddendum none # no default banner path #Banner none # Allow client to pass locale environment variables AcceptEnv LANG LC_* # override default of no subsystems Subsystem sftp /usr/lib/openssh/sftp-server # Example of overriding settings on a per-user basis #Match User anoncvs # X11Forwarding no # AllowTcpForwarding no # PermitTTY no # ForceCommand cvs server
/etc/resolv.conf
# This file was automatically generated by WSL. To stop automatic generation of this file, add the following entry to /etc/wsl.conf: # [network] # generateResolvConf = false nameserver 172.31.224.1
有没有大佬知道问题出在哪?万分感谢!
可能的排查方向和解决办法
我之前也碰到过类似的WSL连Windows端口的问题,给你几个排查思路试试:
先确认Vagrant的端口转发真的生效了
在Windows主机上打开命令提示符,用netstat -ano | findstr :2222看看有没有进程在监听2222端口。如果没找到,那说明Vagrant的端口转发没配置对,得重启Vagrant或者检查Vagrantfile里的转发规则(默认应该是config.vm.network "forwarded_port", guest: 22, host: 2222)。WSL访问Windows主机的正确IP
你用/etc/resolv.conf里的nameserver IP其实是WSL的虚拟网关,但有时候这个网关可能不通。试试在Windows主机上用ipconfig找本地的以太网/无线网卡的IP(比如192.168.x.x),然后在WSL里用这个IP加2222端口试试ssh {username}@{Windows本地IP} -p 2222。如果是WSL 2的话,它是独立的虚拟机,localhost不会指向Windows主机,必须用Windows的本地IP才行;WSL 1则和Windows共享网络栈,localhost就能直接用。防火墙规则要配全
你说加了防火墙规则,但可能没覆盖到位:- 要同时配置入站规则和出站规则,允许TCP协议的2222端口。
- 规则要应用到所有网络配置文件(域、专用、公网),不然可能在某些网络环境下不生效。
- 可以临时关闭Windows防火墙试试,如果能连上,那就是防火墙规则的问题,再回去调整规则。
用SSH调试模式定位问题
试试执行ssh -v {username}@{IP} -p 2222,看详细的调试输出,能看到连接卡在哪个阶段——是DNS解析问题、TCP握手失败还是认证阶段的问题,这样能更精准定位。
备注:内容来源于stack exchange,提问作者Santiago Henao Gonzalez

