SSH connections being dropped by ZyWALL 10



Hello all,

I am running an OpenSSH 4.3 server on an embedded Linux system, so I
have turned on the ClientAliveInterval and TCPKeepAlive options in
sshd_config. ClientAliveInterval is set to 10, and the OS's TCP
keep-alive settings are time = 10, probes = 5, and intvl = 10. (I need
it all low b/c server processes could be holding system-wide locks.)

If I connect to the SSH server directly (i.e., without a firewall in
between), then those settings work fine; server processes die when the
connection is down and stay up when it's up. However, here's my problem:
if I connect from outside my ZyWALL 10 firewall, then the connection is
dropped after about a minute of user inactivity.

The weird thing is that if I connect from outside the firewall via
_Telnet_ (which is using TCP keep-alives too), then it works correctly.
And the _other_ weird thing is that if I use a cheap consumer firewall
instead (D-Link DI-604), then SSH works correctly too. It's only SSH
with the ZyWALL 10 that messes up.

This seems to implicate the SSH-level keep-alives and their interaction
with the ZyWALL, which makes no sense to me because aren't they just
data in the encrypted TCP stream?

Any suggestions would be welcome.

Thanks,

Tristan



Relevant Pages

  • Re: CEICW fails at firewall config
    ... Do you or do you not have ISA 2000 or ISA 2004 installed on the SBS server? ... Do you have 2 NICs in the SBS? ... CEICW fails on firewall configuration every time. ... >>> Call to Creating the protected networks access rule returned ok. ...
    (microsoft.public.windows.server.sbs)
  • Re: Recycler security issues on IIS server
    ... > latest upates to the server. ... > like to see the server put behind our firewall, ... other software, install all patches, IISlockdown, URLscan, use the correct ... the procedures you follow may vary depending on your security needs. ...
    (microsoft.public.inetserver.iis.security)
  • Re: ISA SERVER NOT STARTING
    ... I delete the nat/basic firewall and stop and started the RRAS an tried to ... There were no critical events in the DNS Server Log in the last 24 hours. ... An error occurred during logon ... Caller User Name: - ...
    (microsoft.public.windows.server.sbs)
  • Re: For Microsoft Partners and Customers Who Cant Download or Access
    ... to reconfigure the firewall, but to use a static IP on your client ... and to make sure that the DNS server entries on the client are ... Microsoft for msdn2.microsoft.com. ... use a static IP and set the DNS server addresses to the DNS ...
    (microsoft.public.dotnet.general)
  • RE: Is this as bad as it seems?
    ... The network being protected by the router or firewall is still vulnerable to ... > circumvented - the administrator has explicitly allowed HTTP traffic on ... this exploit has the effect of allowing the attacker to send *INBOUND* HTTP ... The HTTP server (located on the internal network or anywhere else that is ...
    (Security-Basics)