华三S5560交换机 version 7.1.070, Release 6126P13
本地局域网连接正常,总部无法连接
设备debug日志
The current terminal is enabled to display debugging logs.
*Aug 14 10:40:22:952 2026 zbl SSHS/7/MESSAGE: Received packet type 94.
<zbl>*Aug 14 10:40:32:436 2026 zbl SSHS/7/EVENT: Connection from 10.106.7.79 port 57273
*Aug 14 10:40:32:440 2026 zbl SSHS/7/EVENT: Client protocol version 2.0, client software version SecureCRT_7.1.1 (build 264) SecureCRT
*Aug 14 10:40:32:440 2026 zbl SSHS/7/EVENT: Start new child 480673.
*Aug 14 10:40:32:441 2026 zbl SSHS/7/EVENT: Enabling compatibility mode for protocol 2.0
*Aug 14 10:40:32:441 2026 zbl SSHS/7/EVENT: Local version string SSH-2.0-Comware-7.1.070
*Aug 14 10:40:32:441 2026 zbl SSHS/7/EVENT: Pki-domain-name is not configure.
*Aug 14 10:40:32:442 2026 zbl SSHS/7/EVENT: Pki-domain-name is not configure.
*Aug 14 10:40:32:447 2026 zbl SSHS/7/EVENT: Hostkey string is : ssh-rsa,ssh-dss
*Aug 14 10:40:32:448 2026 zbl SSHS/7/MESSAGE: Prepare packet[20].
*Aug 14 10:40:32:449 2026 zbl SSHS/7/MESSAGE: Received packet type 20.
*Aug 14 10:40:32:449 2026 zbl SSHS/7/EVENT: Received SSH2_MSG_KEXINIT.
*Aug 14 10:40:32:450 2026 zbl SSHS/7/EVENT: My proposal kex:
*Aug 14 10:40:32:450 2026 zbl SSHS/7/EVENT: Kex strings(0): ecdh-sha2-nistp256,ecdh-sha2-nistp384,diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha1,diffie-hellman-group1-sha1
*Aug 14 10:40:32:450 2026 zbl SSHS/7/EVENT: Kex strings(1): ssh-rsa,ssh-dss
*Aug 14 10:40:32:451 2026 zbl SSHS/7/EVENT: Kex strings(2): aes128-ctr,aes192-ctr,aes256-ctr,AEAD_AES_128_GCM,AEAD_AES_256_GCM,aes128-cbc,3des-cbc,aes256-cbc,des-cbc
*Aug 14 10:40:32:451 2026 zbl SSHS/7/EVENT: Kex strings(3): aes128-ctr,aes192-ctr,aes256-ctr,AEAD_AES_128_GCM,AEAD_AES_256_GCM,aes128-cbc,3des-cbc,aes256-cbc,des-cbc
*Aug 14 10:40:32:451 2026 zbl SSHS/7/EVENT: Kex strings(4): hmac-sha2-256,hmac-sha2-512,hmac-sha1,hmac-md5,hmac-sha1-96,hmac-md5-96
*Aug 14 10:40:32:451 2026 zbl SSHS/7/EVENT: Kex strings(5): hmac-sha2-256,hmac-sha2-512,hmac-sha1,hmac-md5,hmac-sha1-96,hmac-md5-96
*Aug 14 10:40:32:452 2026 zbl SSHS/7/EVENT: Kex strings(6): none,zlib,zlib@openssh.com
*Aug 14 10:40:32:452 2026 zbl SSHS/7/EVENT: Kex strings(7): none,zlib,zlib@openssh.com
*Aug 14 10:40:32:452 2026 zbl SSHS/7/EVENT: Kex strings(8):
*Aug 14 10:40:32:452 2026 zbl SSHS/7/EVENT: Kex strings(9):
*Aug 14 10:40:32:453 2026 zbl SSHS/7/EVENT: Peer proposal kex:
*Aug 14 10:40:32:453 2026 zbl SSHS/7/EVENT: Kex strings(0): diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1,diffie-hellman-group1-sha1
*Aug 14 10:40:32:453 2026 zbl SSHS/7/EVENT: Kex strings(1): ssh-dss,ssh-rsa,x509v3-sign-rsa,x509v3-sign-dss
*Aug 14 10:40:32:453 2026 zbl SSHS/7/EVENT: Kex strings(2): aes256-ctr,aes192-ctr,aes128-ctr,aes256-cbc,aes192-cbc,aes128-cbc,twofish-cbc,blowfish-cbc,3des-cbc,arcfour
*Aug 14 10:40:32:454 2026 zbl SSHS/7/EVENT: Kex strings(3): aes256-ctr,aes192-ctr,aes128-ctr,aes256-cbc,aes192-cbc,aes128-cbc,twofish-cbc,blowfish-cbc,3des-cbc,arcfour
*Aug 14 10:40:32:454 2026 zbl SSHS/7/EVENT: Kex strings(4): hmac-sha1,hmac-sha1-96,hmac-md5,hmac-md5-96,umac-64@openssh.com
*Aug 14 10:40:32:455 2026 zbl SSHS/7/EVENT: Kex strings(5): hmac-sha1,hmac-sha1-96,hmac-md5,hmac-md5-96,umac-64@openssh.com
*Aug 14 10:40:32:455 2026 zbl SSHS/7/EVENT: Kex strings(6): none
*Aug 14 10:40:32:456 2026 zbl SSHS/7/EVENT: Kex strings(7): none
*Aug 14 10:40:32:456 2026 zbl SSHS/7/EVENT: Kex strings(8):
*Aug 14 10:40:32:456 2026 zbl SSHS/7/EVENT: Kex strings(9):
*Aug 14 10:40:32:457 2026 zbl SSHS/7/EVENT: Kex: client->server, Encrypt: aes256-ctr, HMAC: hmac-sha1, Compress: none
*Aug 14 10:40:32:457 2026 zbl SSHS/7/EVENT: Kex: server->client, Encrypt: aes256-ctr, HMAC: hmac-sha1, Compress: none
*Aug 14 10:40:32:594 2026 zbl SSHS/7/EVENT: Expecting packet type 30.
*Aug 14 10:40:32:595 2026 zbl SSHS/7/MESSAGE: Received packet type 30.
*Aug 14 10:40:32:682 2026 zbl SSHS/7/MESSAGE: Prepare packet[31].
*Aug 14 10:40:32:683 2026 zbl SSHS/7/MESSAGE: Prepare packet[21].
*Aug 14 10:40:32:683 2026 zbl SSHS/7/EVENT: Set new keys: mode=1
*Aug 14 10:40:32:684 2026 zbl SSHS/7/EVENT: Expecting packet type 21.
*Aug 14 10:40:32:701 2026 zbl SSHS/7/EVENT: Set new keys: mode=0
*Aug 14 10:40:32:701 2026 zbl SSHS/7/MESSAGE: Received packet type 21.
*Aug 14 10:40:32:701 2026 zbl SSHS/7/EVENT: KEX done.
*Aug 14 10:40:32:702 2026 zbl SSHS/7/MESSAGE: Received packet type 5.
*Aug 14 10:40:32:702 2026 zbl SSHS/7/EVENT: Received SSH2_MSG_SERVICE_REQUEST.
*Aug 14 10:40:32:703 2026 zbl SSHS/7/MESSAGE: Prepare packet[6].
*Aug 14 10:40:32:705 2026 zbl SSHS/7/MESSAGE: Received packet type 50.
*Aug 14 10:40:32:706 2026 zbl SSHS/7/EVENT: Received SSH2_MSG_USERAUTH_REQUEST.
*Aug 14 10:40:32:706 2026 zbl SSHS/7/EVENT: Username: xfzjwd, service: ssh-connection, method: none
*Aug 14 10:40:32:707 2026 zbl SSHS/7/EVENT: PAM: initializing for "xfzjwd", service:login, domain:
*Aug 14 10:40:33:043 2026 zbl SSHS/7/EVENT: Try authentication method none.
*Aug 14 10:40:33:043 2026 zbl SSHS/7/EVENT: Failed none for xfzjwd from 10.106.7.79 port 57273.
*Aug 14 10:40:33:044 2026 zbl SSHS/7/EVENT: Get authentication methods: password
*Aug 14 10:40:33:044 2026 zbl SSHS/7/MESSAGE: Prepare packet[51].
*Aug 14 10:40:33:049 2026 zbl SSHS/7/MESSAGE: Received packet type 50.
*Aug 14 10:40:33:049 2026 zbl SSHS/7/EVENT: Received SSH2_MSG_USERAUTH_REQUEST.
*Aug 14 10:40:33:050 2026 zbl SSHS/7/EVENT: Username: xfzjwd, service: ssh-connection, method: password
*Aug 14 10:40:33:050 2026 zbl SSHS/7/EVENT: Try authentication method password.
*Aug 14 10:40:33:050 2026 zbl SSHS/7/EVENT: Password authentication and authorization.
*Aug 14 10:40:33:088 2026 zbl SSHS/7/EVENT: PAM: Get work directory flash:.
*Aug 14 10:40:33:089 2026 zbl SSHS/7/EVENT: PAM: Get role list network-admin,network-operator.
*Aug 14 10:40:33:089 2026 zbl SSHS/7/EVENT: PAM: password authentication accepted for xfzjwd.
*Aug 14 10:40:33:089 2026 zbl SSHS/7/EVENT: PAM: accounting.
*Aug 14 10:40:33:091 2026 zbl SSHS/7/EVENT: PAM: account management : 0 (success)
%Aug 14 10:40:33:091 2026 zbl SSHS/6/SSHS_LOG: Accepted password for xfzjwd from 10.106.7.79 port 57273.
*Aug 14 10:40:33:091 2026 zbl SSHS/7/MESSAGE: Prepare packet[52].
*Aug 14 10:40:33:092 2026 zbl SSHS/7/EVENT: Entering interactive session for SSH2.
*Aug 14 10:40:33:093 2026 zbl SSHS/7/EVENT: Initiate server message dispatch, compatibility:1/0
*Aug 14 10:40:33:113 2026 zbl SSHS/7/MESSAGE: Received packet type 90.
*Aug 14 10:40:33:114 2026 zbl SSHS/7/EVENT: Received SSH2_MSG_CHANNEL_OPEN: ctype session, rchan 0, win 131072, max 32768
*Aug 14 10:40:33:117 2026 zbl SSHS/7/EVENT: Received session request.
*Aug 14 10:40:33:117 2026 zbl SSHS/7/EVENT: Channel 0: new [server-session]
*Aug 14 10:40:33:117 2026 zbl SSHS/7/EVENT: Session id 0 unused.
*Aug 14 10:40:33:119 2026 zbl SSHS/7/EVENT: Session opened: session 0, link with channel 0
*Aug 14 10:40:33:119 2026 zbl SSHS/7/MESSAGE: Prepare packet[91].
*Aug 14 10:40:33:130 2026 zbl SSHS/7/MESSAGE: Received packet type 98.
*Aug 14 10:40:33:130 2026 zbl SSHS/7/EVENT: Received SSH2_MSG_CHANNEL_REQUEST: channel 0, request pty-req, reply 1
*Aug 14 10:40:33:130 2026 zbl SSHS/7/EVENT: Channel request: user xfzjwd, service type 1 rtype:pty-req
*Aug 14 10:40:33:152 2026 zbl SSHS/7/EVENT: Open pty: pseudo-terminal-master(35), pseudo-terminal-sub(34)
*Aug 14 10:40:33:154 2026 zbl SSHS/7/MESSAGE: Prepare packet[99].
*Aug 14 10:40:33:178 2026 zbl SSHS/7/MESSAGE: Received packet type 98.
*Aug 14 10:40:33:178 2026 zbl SSHS/7/EVENT: Received SSH2_MSG_CHANNEL_REQUEST: channel 0, request shell, reply 1
*Aug 14 10:40:33:179 2026 zbl SSHS/7/EVENT: Channel request: user xfzjwd, service type 1 rtype:shell
*Aug 14 10:40:33:192 2026 zbl SSHS/7/EVENT: Channel 0: read_fd 37 is a TTY.
*Aug 14 10:40:33:192 2026 zbl SSHS/7/MESSAGE: Prepare packet[93].
*Aug 14 10:40:33:199 2026 zbl SSHS/7/MESSAGE: Prepare packet[99].
*Aug 14 10:40:33:418 2026 zbl SSHS/7/ERROR: Read error from remote host 10.106.7.79: Connection reset by peer
%Aug 14 10:40:33:419 2026 zbl SSHS/6/SSHS_DISCONNECT: SSH user xfzjwd (IP: 10.106.7.79) disconnected from the server.
*Aug 14 10:40:33:419 2026 zbl SSHS/7/EVENT: PAM: cleanup
*Aug 14 10:40:33:430 2026 zbl SSHS/7/EVENT: Close pty: pseudo-terminal-master(-1), pseudo-terminal-sub(34)
*Aug 14 10:40:54:910 2026 zbl SSHS/7/EVENT: Connection from 10.106.7.79 port 57289
*Aug 14 10:40:54:914 2026 zbl SSHS/7/EVENT: Start new child 480676.
*Aug 14 10:40:55:037 2026 zbl SSHS/7/EVENT: Client protocol version 2.0, client software version OpenSSH_10.2
*Aug 14 10:40:55:037 2026 zbl SSHS/7/EVENT: Enabling compatibility mode for protocol 2.0
*Aug 14 10:40:55:037 2026 zbl SSHS/7/EVENT: Local version string SSH-2.0-Comware-7.1.070
*Aug 14 10:40:55:038 2026 zbl SSHS/7/EVENT: Pki-domain-name is not configure.
*Aug 14 10:40:55:038 2026 zbl SSHS/7/EVENT: Pki-domain-name is not configure.
*Aug 14 10:40:55:043 2026 zbl SSHS/7/EVENT: Hostkey string is : ssh-rsa,ssh-dss
*Aug 14 10:40:55:044 2026 zbl SSHS/7/MESSAGE: Prepare packet[20].
*Aug 14 10:40:55:051 2026 zbl SSHS/7/MESSAGE: Received packet type 20.
*Aug 14 10:40:55:052 2026 zbl SSHS/7/EVENT: Received SSH2_MSG_KEXINIT.
*Aug 14 10:40:55:052 2026 zbl SSHS/7/EVENT: My proposal kex:
*Aug 14 10:40:55:052 2026 zbl SSHS/7/EVENT: Kex strings(0): ecdh-sha2-nistp256,ecdh-sha2-nistp384,diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha1,diffie-hellman-group1-sha1
*Aug 14 10:40:55:053 2026 zbl SSHS/7/EVENT: Kex strings(1): ssh-rsa,ssh-dss
*Aug 14 10:40:55:053 2026 zbl SSHS/7/EVENT: Kex strings(2): aes128-ctr,aes192-ctr,aes256-ctr,AEAD_AES_128_GCM,AEAD_AES_256_GCM,aes128-cbc,3des-cbc,aes256-cbc,des-cbc
*Aug 14 10:40:55:054 2026 zbl SSHS/7/EVENT: Kex strings(3): aes128-ctr,aes192-ctr,aes256-ctr,AEAD_AES_128_GCM,AEAD_AES_256_GCM,aes128-cbc,3des-cbc,aes256-cbc,des-cbc
*Aug 14 10:40:55:054 2026 zbl SSHS/7/EVENT: Kex strings(4): hmac-sha2-256,hmac-sha2-512,hmac-sha1,hmac-md5,hmac-sha1-96,hmac-md5-96
*Aug 14 10:40:55:054 2026 zbl SSHS/7/EVENT: Kex strings(5): hmac-sha2-256,hmac-sha2-512,hmac-sha1,hmac-md5,hmac-sha1-96,hmac-md5-96
*Aug 14 10:40:55:054 2026 zbl SSHS/7/EVENT: Kex strings(6): none,zlib,zlib@openssh.com
*Aug 14 10:40:55:055 2026 zbl SSHS/7/EVENT: Kex strings(7): none,zlib,zlib@openssh.com
*Aug 14 10:40:55:055 2026 zbl SSHS/7/EVENT: Kex strings(8):
*Aug 14 10:40:55:055 2026 zbl SSHS/7/EVENT: Kex strings(9):
*Aug 14 10:40:55:055 2026 zbl SSHS/7/EVENT: Peer proposal kex:
*Aug 14 10:40:55:056 2026 zbl SSHS/7/EVENT: Kex strings(0): mlkem768x25519-sha256,sntrup761x25519-sha512,sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@***.***,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256,ext-info-c,kex-strict-c-v00@openssh.com
*Aug 14 10:40:55:056 2026 zbl SSHS/7/EVENT: Kex strings(1): rsa-sha2-512-cert-v01@openssh.com,rsa-sha2-256-cert-v01@openssh.com,rsa-sha2-512,rsa-sha2-256,ssh-ed25519-cert-v01@openssh.com,ecdsa-sha2-nistp256-cert-v01@openssh.com,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp521-cert-v01@openssh.com,sk-ssh-ed25519-cert-v01@openssh.com,sk-ecdsa-sha2-nistp256-cert-v01@openssh.com,ssh-ed25519,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,sk-ssh-ed25519@openssh.com,sk-ecdsa-sha2-nistp256@openssh.com
*Aug 14 10:40:55:056 2026 zbl SSHS/7/EVENT: Kex strings(2): chacha20-poly1305@openssh.com,aes128-gcm@openssh.com,aes256-gcm@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr
*Aug 14 10:40:55:056 2026 zbl SSHS/7/EVENT: Kex strings(3): chacha20-poly1305@openssh.com,aes128-gcm@openssh.com,aes256-gcm@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr
*Aug 14 10:40:55:057 2026 zbl SSHS/7/EVENT: Kex strings(4): umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1
*Aug 14 10:40:55:057 2026 zbl SSHS/7/EVENT: Kex strings(5): umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1
*Aug 14 10:40:55:057 2026 zbl SSHS/7/EVENT: Kex strings(6): zlib@openssh.com,none
*Aug 14 10:40:55:057 2026 zbl SSHS/7/EVENT: Kex strings(7): zlib@openssh.com,none
*Aug 14 10:40:55:058 2026 zbl SSHS/7/EVENT: Kex strings(8):
*Aug 14 10:40:55:058 2026 zbl SSHS/7/EVENT: Kex strings(9):
*Aug 14 10:40:55:058 2026 zbl SSHS/7/EVENT: Kex: client->server, Encrypt: aes128-ctr, HMAC: hmac-sha2-256, Compress: zlib@openssh.com
*Aug 14 10:40:55:059 2026 zbl SSHS/7/EVENT: Kex: server->client, Encrypt: aes128-ctr, HMAC: hmac-sha2-256, Compress: zlib@openssh.com
%Aug 14 10:40:55:059 2026 zbl SSHS/6/SSHS_ALGORITHM_MISMATCH: SSH client 10.106.7.79 failed to log in because of public key mismatch.
*Aug 14 10:40:55:060 2026 zbl SSHS/7/ERROR: No host_key algorithm
%Aug 14 10:40:55:060 2026 zbl SSHS/6/SSHS_DISCONNECT: SSH user (null) (IP: 10.106.7.79) disconnected from the server.
S5560‑7.1.070P13 SSH 故障日志分析
现象:
SecureCRT7.1.1:密码认证完全成功,已经进入 shell 会话,马上报 Read error from remote host 10.106.7.79: Connection reset by peer,连接被客户端侧重置。
OpenSSH_10.2 新版客户端:直接报 SSHS_ALGORITHM_MISMATCH / No host_key algorithm,协商直接失败。
本地局域网访问正常,总部跨网段出现问题。
日志拆解两个问题
现象 1:SecureCRT7.1.1,认证通过,进入会话立刻被断开
plaintext
PAM: password authentication accepted for xfzjwd
Accepted password for xfzjwd from 10.106.7.79 port 57273
Entering interactive session for SSH2.
......
SSHS/7/ERROR: Read error from remote host 10.106.7.79: Connection reset by peer
✅交换机侧 SSH 认证完全成功,账号密码、kex、加密、PAM 全部正常;不是交换机拒绝,是对端(总部客户端 / 中间网络设备)主动 TCP RST 断开连接。
关键点:Connection reset by peer = TCP 对端发送 RST 报文断开,不是交换机主动关闭。
本地局域网正常,跨总部 VPN / 广域网出现,高度怀疑:中间防火墙 / 安全设备会话超时、IPS 特征误杀 SSH 流量、TCP MSS/MTU 问题。
现象 2:OpenSSH 10.2 新版本客户端直接协商失败
plaintext
SSHS_ALGORITHM_MISMATCH: SSH client 10.106.7.79 failed to log in because of public key mismatch.
No host_key algorithm
S5560 版本 Release 6126P13,SSH 主机密钥仅生成:ssh‑rsa、ssh‑dss。
新版 OpenSSH 10.x 默认禁用 ssh‑rsa (sha1)、彻底废弃 ssh‑dss,客户端不再携带这两类主机密钥算法;交换机没有 ecdsa/ed25519 主机密钥,没有共同匹配的 host‑key 算法,协商直接失败。
这是老 Comware7 版本和现代新版 OpenSSH 客户端的经典兼容 bug。
问题分开处理
一、OpenSSH10.x 客户端算法不兼容(No host_key algorithm)
方案 A:交换机生成 ecdsa 主机密钥(推荐)
shell
#生成ecdsa‑nistp256主机密钥
public‑key local‑key create ecdsa nistp256
#查看已经生成的主机密钥
display public‑key local‑key ssh
生成后,SSH 服务会自动加载 ecdsa 主机密钥,新版 OpenSSH 客户端就可以匹配上。
注意:老版本 S5560‑6126P13不支持 ed25519 密钥,仅支持 ecdsa‑nistp256。
方案 B:客户端临时兼容(临时应急,不推荐长期)
OpenSSH 客户端配置,强制启用 ssh‑rsa 算法:
plaintext
Host *
HostkeyAlgorithms +ssh‑rsa
PubkeyAcceptedAlgorithms +ssh‑rsa
二、SecureCRT7.1.1 认证成功后立刻被 RST 断开(重点!广域网 VPN 场景)
日志确认交换机 SSH 服务已经完成登录、创建 pty 终端,还没输出命令行提示符,TCP 被对端 RST。
本地局域网正常,跨总部 VPN 线路故障,故障不在交换机本身,在中间传输链路的安全设备。
排查点
中间防火墙 / IPS/ACG 设备会话超时
VPN / 防火墙 TCP 会话老化时间太短,SSH 协商交互过程时间略长,会话被设备删除,发出 RST 断开。
检查总部‑分支之间防火墙:TCP 会话超时,ssh 会话超时,调大 TCP 非活跃会话超时时间。
部分 IPS 有 SSH 协议检测,误判定异常报文直接 RST 杀掉会话。
MTU/MSS 问题(VPN 场景高频)
GRE/IPSEC VPN 封装,报文过大分片异常。
测试:在 SecureCRT 中开启 SSH 的 TCP NODELAY,修改 MSS;
交换机侧可配置:
shell
system‑view
ip tcp mss 1300
抓包定位
在交换机镜像抓 SSH(22 端口)报文,看 RST 报文源 IP:
如果 RST 来自客户端 IP:总部终端 / 终端安全软件杀毒软件拦截;
如果 RST 来自中间防火墙 IP:边界安全设备杀掉会话。
命令交换机开启本地报文捕获(Comware7):
shell
diagnose
packet‑capture interface GigabitEthernet x/x match tcp destination‑port 22
ACL 过滤检查
确认交换机本地 ACL 没有对总部网段做异常分片 / 特殊过滤:
shell
display packet‑filter
三、完整检查命令,现场直接执行
shell
display version
display public‑key local‑key ssh
display ssh server status
display acl resource
display packet‑filter
display logbuffer | include TCP
四、临时规避测试手段
总部 SecureCRT 连接,关闭压缩;关闭 GCM 加密算法,强制选用 aes256‑ctr;
测试 telnet(仅定位故障,不要长期使用),确认 TCP 链路是否稳定。
总部电脑长 ping 交换机管理 IP,‑l 设置大包,看是否丢包,确认 VPN 链路 MTU 问题。
总结
OpenSSH10.x 报错No host_key algorithm:交换机生成 ecdsa nistp256 本地公钥即可解决。
SecureCRT7.1.1 密码登录成功马上Connection reset by peer:交换机 SSH 服务本身没问题,是中间 VPN / 防火墙 / IPS 发出 TCP RST 切断会话,优先排查中间网络设备会话超时、IPS 误阻断、MTU/MSS。
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
mobaxterm和SecureCRT都不行