[Vpn-help] SSH connection hang with beta 2

Tai-hwa Liang avatar at mmlab.cse.yzu.edu.tw
Tue May 8 20:43:39 CDT 2007


On Tue, 8 May 2007, Matthew Grooms wrote:
[...]
> I ran a battery of tests with all the combinations I could think of to 
> reproduce the problem but was unsuccessful. What operating system are you 
> using on the client side? Are you performing the tests from a cable or dsl 
> modem over the internet? If so, is there a firewall/router being used between

   I am using Windows XP(default firewall) over an ADSL line(PPPoE on
ADSL modem).  A colleague of mine who happens to have the same hanging
problem runs similar configuration except he's using Windows' PPPoE client.

> the client and the gateway?

   The gateway is running pf on FreeBSD 6.2.  I tried to disable gateway
firewall temporarily by using "pfctl -d" but PuTTY still hangs for
a couple of minutes in my testing case.

> My gut feeling is that esp packet fragments are not getting back to the 
> client for re-assembly. Using a "find /" over an ssh connection makes me 
> think that the bulk of the traffic would be emitted from the server destined 
> to the ssh client. There wouldn't be much sent back to the server with the 
> exception of the ssh protocol window adjustments. I don't think that kind of 
> packet would ever get big enough to warrant fragmentation. Maybe we can look 
> at some packet dumps to determine for sure in what direction the tcp stall is 
> happening.

   Is the Trace Utility included in VPN client enough to get the required dump?
Otherwise, it looks to me that I have to install ethereal WIN32....

-- 
Cheers,

Tai-hwa Liang



More information about the vpn-help mailing list