Re: OpenSSH's sshd drops connections



On 26 jul, Nejc Škoberne wrote:
I manage around 50 FreeBSD servers and I have created a script which does
some work every 5 minutes. Actually this script transfers some files to/from
the central server, which is running a OpenSSH's sshd
(OpenSSH_4.5p1 FreeBSD-20061110, OpenSSL 0.9.7e-p1 25 Oct 2004). So I use
sftp (I have also tried scp) on client sides to perform the task.

The problem is, that (apparently because all the servers start transferring
files at approximately the same time), some clients are able to do the transfers
and others are not.
[deleted]
Do you have any ideas why the central server's sshd drops the connections?

The ssh server will only allow a certain sessions at a time to be in the
authentication phase. This is controlled by the MaxStartups option,
which defaults to 10. The symptoms you see matches what happens when
this triggers.

Note that setting up the encrypted tunnel is potentially quite stressful
for the machine, and if the time gets more synchronized (think ntp) this
will probably become a bigger problem. The best solution is, IMHO, to
add a random delay to the clients rather than just increasing
MaxStartups.

/MaF
--
Martin Forssen <maf@xxxxxxxxxxx> Development Manager
Phone: +46 31 7744361 AppGate Network Security AB



Relevant Pages

  • RE: 7.1-STABLE Sun Mar 29 01:06:46 ADT 2009 Locks up ...
    ... Server seems to hang in intervals of about 8 hours. ... <ACPI PCI bus> on pcib0 ... 0xd8000000-0xd9ffffff,0xdc100000-0xdc100fff irq 48 at device 0.0 on ... da0: 100.000MB/s transfers ...
    (freebsd-stable)
  • Network performance issues when writing to disk (5.2.1-RELEASE)
    ... The server has two miibus-based NICs: a WAN link via dc1 and a switched LAN ... File transfers to the server experience terrible ... replicated with the server connected directly to any of the clients with the ...
    (freebsd-performance)
  • Re: New to BIND - Setting up slaveserver
    ... transfers from the ip address supplied. ... recursion is how you run a caching server. ... "authoritative" data found in local zone files you configure. ... Since the folder "named" is owned by root and I created a folder called ...
    (comp.protocols.dns.bind)
  • Re: Zone Alarm connects to the Internet on startup
    ... updates all these stuff will be tranfered to the Microsofts server. ... When a security software act as a spyware tool and no one can ... Several days ago I read a statement that Sygates Personal Firewall ... unallowed transfers, connection, etc. ...
    (comp.security.firewalls)
  • 6.2 Freezes
    ... Our server is running for awhile (sometimes 1 day, ... pci0: <PCI bus> on pcib0 ... <Parallel port bus> on ppc0 ... ses0: 3.300MB/s transfers ...
    (freebsd-questions)