Firewall-1

Re: [FW-1] ssh through vpn

Subject: Re: [FW-1] ssh through vpn
From: pkc_mls <pkc_mls AT YAHOO DOT FR>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Date: Thu, 19 Oct 2006 10:25:15 +0200
robby AT cauwerts DOT be a écrit :
Hi,

Most of the times this is a resolver problem.
Change your sshd_config:

#UseDNS yes
to
UseDNS no

&& restart sshd daemon

man sshd and http://marc.theaimsgroup.com/?t=105139788100001&r=1&w=2

Kr.
Robby

I tried the modification above, but I still have the same problem.

I saw that the MSS are modified (by the vpn gateway or the vpn edge).

           client      splat      vpn edge      server
syn           1360  ->  1360   ->   1280     ->   1280
syn-ack       1380  <-  1380   <-   1460     <-   1460


has anyone a running config with an ssh through vpn ?
if so, could he detail the installation ?
(ssh client, ssh server, gateways, vpn settings).

thanks

On 10/17/06, pkc_mls <pkc_mls AT yahoo DOT fr> wrote:
Hi,

I try to setup a config between a splat and a vpn1 edge.

when I try to connect using ftp, the banner comes immediately.
When I try with ssh, I have to wait almost 2 minutes before it asks me
for the login.

the tracker shows some out of state connections, but even if I choose
not to drop out of state
tcp (on splat and vpn1), it's always slow.

has anyone ever seen this ?

thanks







___________________________________________________________________________ Découvrez une nouvelle façon d'obtenir des réponses à toutes vos questions !
Demandez à ceux qui savent sur Yahoo! Questions/Réponses
http://fr.answers.yahoo.com

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================


=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================



        

        
                
___________________________________________________________________________ D�uvrez une nouvelle fa� d'obtenir des r�nses �outes vos questions ! Demandez �eux qui savent sur Yahoo! Questions/R�nses
http://fr.answers.yahoo.com

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================

<Prev in Thread] Current Thread [Next in Thread>