Re: [j-nsp] Juniper SRX and ssh freeze

2010-12-23 Thread Florian Weimer
* Julien Goodwin: > For my SRX at the office back when I installed it (9.6 IIRC) *TCP* > keepalives would not extend session timeouts, but *SSH* keepalives > worked very well, that's the ServerAliveInterval setting in OpenSSH. Typically, TCP keepalives happen at such long intervals that they do n

Re: [j-nsp] Juniper SRX and ssh freeze

2010-12-23 Thread Julien Goodwin
On 23/12/10 21:34, Florian Weimer wrote: > * Julien Goodwin: > >> For my SRX at the office back when I installed it (9.6 IIRC) *TCP* >> keepalives would not extend session timeouts, but *SSH* keepalives >> worked very well, that's the ServerAliveInterval setting in OpenSSH. > > Typically, TCP kee

Re: [j-nsp] Juniper SRX and ssh freeze

2010-12-22 Thread Mark Kamichoff
On Wed, Dec 22, 2010 at 07:43:30PM +0100, Maciej Jan Broniarz wrote: > >{primary:node0} > >p...@orb> show configuration applications > >application junos-ssh inactivity-timeout 3600; > > Does junos-ssh applies to any ssh traffic - the one to the srx itself, > and the one to the servers behind an S

Re: [j-nsp] Juniper SRX and ssh freeze

2010-12-22 Thread Maciej Jan Broniarz
Dnia 10-12-20 18:04 użytkownik „Mark Kamichoff” napisał: >On Mon, Dec 20, 2010 at 10:18:27AM -0600, Chris Adams wrote: >> I don't know about the SRX, but I know with the SSG, the ScreenOS >> default timeout for TCP sessions was way too low (IIRC something like >> 5 minutes) and would cause that

Re: [j-nsp] Juniper SRX and ssh freeze

2010-12-21 Thread Barny Sanchez
Yes it is supported in SRX, and you are right not supported in ScreenOS, it drops it. Thanks! - Barny On Dec 21, 2010, at 8:08 PM, "Julien Goodwin" wrote: > On 22/12/10 04:53, Alfred Schweder wrote: >> Does SRX support ssh keepalive (like M- or J-serie)? >> >> SSGs drop the ssh session if th

Re: [j-nsp] Juniper SRX and ssh freeze

2010-12-21 Thread Julien Goodwin
On 22/12/10 04:53, Alfred Schweder wrote: > Does SRX support ssh keepalive (like M- or J-serie)? > > SSGs drop the ssh session if they get a keepalive. > Juniper isn't willing to fix this in the near future ;-( For my SRX at the office back when I installed it (9.6 IIRC) *TCP* keepalives would no

Re: [j-nsp] Juniper SRX and ssh freeze

2010-12-21 Thread Alfred Schweder
Hello > > I don't know about the SRX, but I know with the SSG, the ScreenOS > > default timeout for TCP sessions was way too low (IIRC something like > > 5 minutes) and would cause that. I turned on SSH keepalives to avoid > > the timeout. Does SRX support ssh keepalive (like M- or J-serie)? SS

Re: [j-nsp] Juniper SRX and ssh freeze

2010-12-20 Thread Mark Kamichoff
On Mon, Dec 20, 2010 at 10:18:27AM -0600, Chris Adams wrote: > I don't know about the SRX, but I know with the SSG, the ScreenOS > default timeout for TCP sessions was way too low (IIRC something like > 5 minutes) and would cause that. I turned on SSH keepalives to avoid > the timeout. Yep, the S

Re: [j-nsp] Juniper SRX and ssh freeze

2010-12-20 Thread Chris Adams
Once upon a time, Maciej Jan Broniarz said: > I have a bunch of servers connected to an Juniper SRX. When I log on them via > ssh everything is fine, but when I leave the session idle for a few minutes > it freezes and i have to close the connection and login again. What might be > the issue he

[j-nsp] Juniper SRX and ssh freeze

2010-12-20 Thread Maciej Jan Broniarz
Hi, I have a bunch of servers connected to an Juniper SRX. When I log on them via ssh everything is fine, but when I leave the session idle for a few minutes it freezes and i have to close the connection and login again. What might be the issue here? The problem only occurs when I connect to a