ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    KVM host: refusing connection on ports 22 & 9090

    IT Discussion
    kvm fedora 29 cockpit ssh connections
    7
    26
    1.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • FATeknollogeeF
      FATeknollogee @CloudKnight
      last edited by

      @StuartJordan no such /var/log/auth
      I do have /var/log/secure

      CloudKnightC 1 Reply Last reply Reply Quote 0
      • CloudKnightC
        CloudKnight @FATeknollogee
        last edited by

        @FATeknollogee Sorry I'm used to Debian based distro, yep that sounds right if using fedora. you can also check with journal command:

        journalctl -r /usr/sbin/sshd

        1 Reply Last reply Reply Quote 0
        • black3dynamiteB
          black3dynamite
          last edited by black3dynamite

          Do you have fail2Ban set up on your KVM host?

          FATeknollogeeF 1 Reply Last reply Reply Quote 0
          • FATeknollogeeF
            FATeknollogee @black3dynamite
            last edited by

            @black3dynamite said in KVM host: refusing connection on ports 22 & 9090:

            Do you have fail2Ban set up on your KVM host?

            No

            scottalanmillerS 1 Reply Last reply Reply Quote 0
            • FATeknollogeeF
              FATeknollogee
              last edited by

              Looking through the logs, nothing looks out of place.

              1 Reply Last reply Reply Quote 0
              • scottalanmillerS
                scottalanmiller @FATeknollogee
                last edited by

                @FATeknollogee said in KVM host: refusing connection on ports 22 & 9090:

                @black3dynamite said in KVM host: refusing connection on ports 22 & 9090:

                Do you have fail2Ban set up on your KVM host?

                No

                You definitely want that.

                ObsolesceO 1 Reply Last reply Reply Quote 0
                • ObsolesceO
                  Obsolesce @scottalanmiller
                  last edited by

                  @scottalanmiller said in KVM host: refusing connection on ports 22 & 9090:

                  @FATeknollogee said in KVM host: refusing connection on ports 22 & 9090:

                  @black3dynamite said in KVM host: refusing connection on ports 22 & 9090:

                  Do you have fail2Ban set up on your KVM host?

                  No

                  You definitely want that.

                  For what? If ssh is only strong cert auth that leaves 9090 for Cockpit. Is there a good 9090 config for failtoban?

                  scottalanmillerS 2 Replies Last reply Reply Quote 0
                  • FATeknollogeeF
                    FATeknollogee
                    last edited by

                    The box is behind a firewall & port 22 is only open to a specific IP.

                    1 Reply Last reply Reply Quote 0
                    • scottalanmillerS
                      scottalanmiller @Obsolesce
                      last edited by

                      @Obsolesce said in KVM host: refusing connection on ports 22 & 9090:

                      For what?

                      Security. Otherwise you leave yourself open to brute force attacks. Or even just brute force attempts. Still uses your bandwidth.

                      1 Reply Last reply Reply Quote 0
                      • scottalanmillerS
                        scottalanmiller @Obsolesce
                        last edited by

                        @Obsolesce said in KVM host: refusing connection on ports 22 & 9090:

                        that leaves 9090 for Cockpit.

                        This is true, but automated attacks against Cockpit are way, way more rare. It's a fraction of the attack surface out of the gate.

                        1 Reply Last reply Reply Quote 0
                        • FATeknollogeeF
                          FATeknollogee
                          last edited by

                          Still looking for a fix!!

                          scottalanmillerS 1 Reply Last reply Reply Quote 0
                          • J
                            JasGot
                            last edited by

                            Does anyone use Door Knocking anymore?

                            1 Reply Last reply Reply Quote 0
                            • CloudKnightC
                              CloudKnight
                              last edited by

                              Is it just these ports? is anything else dropping at the same time that your are unaware of on this host? have you tried accessing the host using putty on another machine?

                              FATeknollogeeF 1 Reply Last reply Reply Quote 0
                              • FATeknollogeeF
                                FATeknollogee @CloudKnight
                                last edited by

                                @StuartJordan These are the ports I always need (haven't checked others).
                                I was able to use the new Relay feature on MeshCentral 2 to connect via LAN.

                                CloudKnightC 1 Reply Last reply Reply Quote 1
                                • CloudKnightC
                                  CloudKnight @FATeknollogee
                                  last edited by

                                  no connection issues when using the relay then?

                                  1 Reply Last reply Reply Quote 0
                                  • scottalanmillerS
                                    scottalanmiller @FATeknollogee
                                    last edited by

                                    @FATeknollogee said in KVM host: refusing connection on ports 22 & 9090:

                                    Still looking for a fix!!

                                    Can you ping out from it? Is the gateway missing or wrong? Subnet missing or wrong?

                                    1 Reply Last reply Reply Quote 0
                                    • 1
                                    • 2
                                    • 1 / 2
                                    • First post
                                      Last post