Re: [j-nsp] Juniper SRX and ssh freeze

2010-12-23 Thread Julien Goodwin
On 23/12/10 21:34, Florian Weimer wrote: * Julien Goodwin: For my SRX at the office back when I installed it (9.6 IIRC) *TCP* keepalives would not extend session timeouts, but *SSH* keepalives worked very well, that's the ServerAliveInterval setting in OpenSSH. Typically, TCP keepalives

Re: [j-nsp] Juniper SRX and ssh freeze

2010-12-23 Thread Florian Weimer
* Julien Goodwin: For my SRX at the office back when I installed it (9.6 IIRC) *TCP* keepalives would not extend session timeouts, but *SSH* keepalives worked very well, that's the ServerAliveInterval setting in OpenSSH. Typically, TCP keepalives happen at such long intervals that they do not

Re: [j-nsp] Juniper SRX and ssh freeze

2010-12-22 Thread Maciej Jan Broniarz
Dnia 10-12-20 18:04 użytkownik „Mark Kamichoff” p...@prolixium.com napisał: On Mon, Dec 20, 2010 at 10:18:27AM -0600, Chris Adams wrote: I don't know about the SRX, but I know with the SSG, the ScreenOS default timeout for TCP sessions was way too low (IIRC something like 5 minutes) and

Re: [j-nsp] Juniper SRX and ssh freeze

2010-12-22 Thread Mark Kamichoff
On Wed, Dec 22, 2010 at 07:43:30PM +0100, Maciej Jan Broniarz wrote: {primary:node0} p...@orb show configuration applications application junos-ssh inactivity-timeout 3600; Does junos-ssh applies to any ssh traffic - the one to the srx itself, and the one to the servers behind an SRX

Re: [j-nsp] Juniper SRX and ssh freeze

2010-12-21 Thread Alfred Schweder
Hello I don't know about the SRX, but I know with the SSG, the ScreenOS default timeout for TCP sessions was way too low (IIRC something like 5 minutes) and would cause that. I turned on SSH keepalives to avoid the timeout. Does SRX support ssh keepalive (like M- or J-serie)? SSGs drop

Re: [j-nsp] Juniper SRX and ssh freeze

2010-12-21 Thread Julien Goodwin
On 22/12/10 04:53, Alfred Schweder wrote: Does SRX support ssh keepalive (like M- or J-serie)? SSGs drop the ssh session if they get a keepalive. Juniper isn't willing to fix this in the near future ;-( For my SRX at the office back when I installed it (9.6 IIRC) *TCP* keepalives would not

Re: [j-nsp] Juniper SRX and ssh freeze

2010-12-21 Thread Barny Sanchez
Yes it is supported in SRX, and you are right not supported in ScreenOS, it drops it. Thanks! - Barny On Dec 21, 2010, at 8:08 PM, Julien Goodwin jgood...@studio442.com.au wrote: On 22/12/10 04:53, Alfred Schweder wrote: Does SRX support ssh keepalive (like M- or J-serie)? SSGs drop the

Re: [j-nsp] Juniper SRX and ssh freeze

2010-12-20 Thread Chris Adams
Once upon a time, Maciej Jan Broniarz gau...@gausus.net said: I have a bunch of servers connected to an Juniper SRX. When I log on them via ssh everything is fine, but when I leave the session idle for a few minutes it freezes and i have to close the connection and login again. What might be

Re: [j-nsp] Juniper SRX and ssh freeze

2010-12-20 Thread Mark Kamichoff
On Mon, Dec 20, 2010 at 10:18:27AM -0600, Chris Adams wrote: I don't know about the SRX, but I know with the SSG, the ScreenOS default timeout for TCP sessions was way too low (IIRC something like 5 minutes) and would cause that. I turned on SSH keepalives to avoid the timeout. Yep, the SRX