Hi,
I'm having an annoying problem using diald in conjunction with SSH.
What I'm trying to do is open an SSH connection to a remote machine,
and have diald *not* cut down the link while the ssh connection is
up (otherwise I would see a broken, useless SSH connection), but other-
wise manage the link as usual - especially close the link quickly af-
ter the SSH connection has been closed.
Two problems:
o (this is not exactly diald-related, but rather an ssh issue, but I
would hope that other people on this list are using SSH ...)
What I first tried to do is simply rely on the keepalive fea-
ture of ssh to keep the link busy, and set a short timeout for
SSH-initiated connections.
However, it seems like diald is not reacting to any keepalive
packets sent by ssh, or ssh is not sending any. I *do* have
'keepalive yes' in both the local ssh_config and the remote
sshd_config. Is there anything special about SSH keepalive
packets that make them invisible to diald in it's out-of-the
box configuration?
o Second thing I tried was set a very long timeout for SSH, and rely
on the !tcp.live feature to shorten the timeout after the
SSH connection went down.
Did I read Lourdes Jones' posting
(Message-ID: <003701bf912f$b3620860$0100a8c0@jones> ) correctly
in that I have to put my 'accept tcp 600 tcp.dest=tcp.ssh'
in the ruleset *after* the !tcp.live rule?
Has anybody got ssh to work without diald cutting the link off, even
if you are away from the ssh window for a bit?
Any help is appreciated,
-Chris
--
---------------------------------------------------------------------
Christian Hamacher | phone: +49-241-80 7912 | So I cheered
Communication Networks | fax : +49-241-8888 242 | up, and sure
University of Technology | [EMAIL PROTECTED] | enough, things
Aachen, Germany | | got worse ...
WWW: http://www.comnets.rwth-aachen.de/~ham
PGP-fingerprint: 85 04 81 E2 8D BC B3 E1 06 7D 1C 45 25 28 6C B6
public key available at keyserver or from my homepage
-
To unsubscribe from this list: send the line "unsubscribe linux-diald" in
the body of a message to [EMAIL PROTECTED]