ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    KVM host: refusing connection on ports 22 & 9090

    Scheduled Pinned Locked Moved IT Discussion
    kvmfedora 29cockpitsshconnections
    26 Posts 7 Posters 1.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • O
      Obsolesce @FATeknollogee
      last edited by

      @FATeknollogee said in KVM host: refusing connection on ports 22 & 9090:

      This past weekend one of my KVM hosts has started acting funny.
      It's refusing connections on ports 22 & 9090.

      I was able to use the new Relay feature on MeshCentral 2 to connect via LAN but this connection only stays on for 15 secs then disconnects.

      Pls throw some crazy ideas my way!!

      What do the logs say?

      C 1 Reply Last reply Reply Quote 1
      • C
        CloudKnight
        last edited by

        Nothing in logs?

        1 Reply Last reply Reply Quote 0
        • C
          CloudKnight @Obsolesce
          last edited by

          @Obsolesce said in KVM host: refusing connection on ports 22 & 9090:

          @FATeknollogee said in KVM host: refusing connection on ports 22 & 9090:

          This past weekend one of my KVM hosts has started acting funny.
          It's refusing connections on ports 22 & 9090.

          I was able to use the new Relay feature on MeshCentral 2 to connect via LAN but this connection only stays on for 15 secs then disconnects.

          Pls throw some crazy ideas my way!!

          What do the logs say?

          Both posted at same time lol...

          1 Reply Last reply Reply Quote 0
          • F
            FATeknollogee
            last edited by

            What logs? I can't connect unless I go hookup a keyboard & monitor.

            D C 2 Replies Last reply Reply Quote 0
            • D
              Dashrender @FATeknollogee
              last edited by

              @FATeknollogee said in KVM host: refusing connection on ports 22 & 9090:

              What logs? I can't connect unless I go hookup a keyboard & monitor.

              Right - that's why I asked about iDRAC or iLo.

              1 Reply Last reply Reply Quote 1
              • C
                CloudKnight @FATeknollogee
                last edited by

                @FATeknollogee Might be a pain in the ass but if you have no other way of connecting?

                1 Reply Last reply Reply Quote 0
                • F
                  FATeknollogee
                  last edited by

                  logs.png

                  1 Reply Last reply Reply Quote 0
                  • C
                    CloudKnight
                    last edited by

                    The Inotify errors are to do with file system. you want ssh logs. /var/log/auth.log

                    F 1 Reply Last reply Reply Quote 0
                    • F
                      FATeknollogee @CloudKnight
                      last edited by

                      @StuartJordan no such /var/log/auth
                      I do have /var/log/secure

                      C 1 Reply Last reply Reply Quote 0
                      • C
                        CloudKnight @FATeknollogee
                        last edited by

                        @FATeknollogee Sorry I'm used to Debian based distro, yep that sounds right if using fedora. you can also check with journal command:

                        journalctl -r /usr/sbin/sshd

                        1 Reply Last reply Reply Quote 0
                        • B
                          black3dynamite
                          last edited by black3dynamite

                          Do you have fail2Ban set up on your KVM host?

                          F 1 Reply Last reply Reply Quote 0
                          • F
                            FATeknollogee @black3dynamite
                            last edited by

                            @black3dynamite said in KVM host: refusing connection on ports 22 & 9090:

                            Do you have fail2Ban set up on your KVM host?

                            No

                            S 1 Reply Last reply Reply Quote 0
                            • F
                              FATeknollogee
                              last edited by

                              Looking through the logs, nothing looks out of place.

                              1 Reply Last reply Reply Quote 0
                              • S
                                scottalanmiller @FATeknollogee
                                last edited by

                                @FATeknollogee said in KVM host: refusing connection on ports 22 & 9090:

                                @black3dynamite said in KVM host: refusing connection on ports 22 & 9090:

                                Do you have fail2Ban set up on your KVM host?

                                No

                                You definitely want that.

                                O 1 Reply Last reply Reply Quote 0
                                • O
                                  Obsolesce @scottalanmiller
                                  last edited by

                                  @scottalanmiller said in KVM host: refusing connection on ports 22 & 9090:

                                  @FATeknollogee said in KVM host: refusing connection on ports 22 & 9090:

                                  @black3dynamite said in KVM host: refusing connection on ports 22 & 9090:

                                  Do you have fail2Ban set up on your KVM host?

                                  No

                                  You definitely want that.

                                  For what? If ssh is only strong cert auth that leaves 9090 for Cockpit. Is there a good 9090 config for failtoban?

                                  S 2 Replies Last reply Reply Quote 0
                                  • F
                                    FATeknollogee
                                    last edited by

                                    The box is behind a firewall & port 22 is only open to a specific IP.

                                    1 Reply Last reply Reply Quote 0
                                    • S
                                      scottalanmiller @Obsolesce
                                      last edited by

                                      @Obsolesce said in KVM host: refusing connection on ports 22 & 9090:

                                      For what?

                                      Security. Otherwise you leave yourself open to brute force attacks. Or even just brute force attempts. Still uses your bandwidth.

                                      1 Reply Last reply Reply Quote 0
                                      • S
                                        scottalanmiller @Obsolesce
                                        last edited by

                                        @Obsolesce said in KVM host: refusing connection on ports 22 & 9090:

                                        that leaves 9090 for Cockpit.

                                        This is true, but automated attacks against Cockpit are way, way more rare. It's a fraction of the attack surface out of the gate.

                                        1 Reply Last reply Reply Quote 0
                                        • F
                                          FATeknollogee
                                          last edited by

                                          Still looking for a fix!!

                                          S 1 Reply Last reply Reply Quote 0
                                          • J
                                            JasGot
                                            last edited by

                                            Does anyone use Door Knocking anymore?

                                            1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 1 / 2
                                            • First post
                                              Last post