クライアントの過剰な受信接続が原因で、SSH経由でクラスタにアクセスできません
環境
- ONTAP 9
- SSH
問題
- 次のエラーでSSH経由でクラスタ管理またはノード管理にアクセスできません
# ssh -vvv admin@clustermgmt.localOpenSSH_7.4p1, OpenSSL 1.0.2k-fips 26 Jan 2017debug1: Reading configuration data /etc/ssh/ssh_configdebug1: /etc/ssh/ssh_config line 62: Applying options for *debug1: Executing proxy command: exec /usr/bin/sss_ssh_knownhostsproxy -p 22 clustermgmt.localdebug1: permanently_set_uid: 0/0debug1: permanently_drop_suid: 0debug1: identity file /root/.ssh/id_rsa type 1debug1: key_load_public: No such file or directorydebug1: identity file /root/.ssh/id_rsa-cert type -1debug1: key_load_public: No such file or directorydebug1: identity file /root/.ssh/id_dsa type -1debug1: key_load_public: No such file or directorydebug1: identity file /root/.ssh/id_dsa-cert type -1debug1: key_load_public: No such file or directorydebug1: identity file /root/.ssh/id_ecdsa type -1debug1: key_load_public: No such file or directorydebug1: identity file /root/.ssh/id_ecdsa-cert type -1debug1: key_load_public: No such file or directorydebug1: identity file /root/.ssh/id_ed25519 type -1debug1: key_load_public: No such file or directorydebug1: identity file /root/.ssh/id_ed25519-cert type -1debug1: Enabling compatibility mode for protocol 2.0debug1: Local version string SSH-2.0-OpenSSH_7.4ssh_exchange_identification: Connection closed by remote host- ストレージ監査ログに接続試行回数が多すぎるため、SSHサービスを非アクティブにできないことが示されています
0000001c.000068ae 00002423 Sun Apr 03 2022 08:17:51 +03:00 [daemon:error] 1 2022-04-03T08:17:51.341021+03:00 node-01 xinetd 6704 - - Deactivating service ssh due to excessive incoming connections. Restarting in 60 seconds.0000001c.000068fd 0000278c Sun Apr 03 2022 08:19:17 +03:00 [daemon:error] 1 2022-04-03T08:19:17.765067+03:00 node-01 xinetd 6704 - - Deactivating service ssh due to excessive incoming connections. Restarting in 60 seconds.ifstatSSHポート22がリスンしていないことを表示します
---- ANYVSERVER IPSpace ----Active Internet connections (including servers)Proto Recv-Q Send-Q Rexmit OOORcv 0-win Local Address Foreign Address (state) VCTX Services Used-CG Req-CG Hash CG-Row CG-Col CG-Class Weight Bytes_Sent Bytes_Rcvd Rwind Swind Cong-win(bytes) Cong-win-thresh(bytes) MSS(bytes) Cong-algo ECNtcp4 0 0 0 0 0 *.22 *.* CLOSED ANY 0x01FFFE7E ------- ------ 0 0 0 ---------------- 0 0 0 0 0 1073725440 1073725440 1220 cubic N/Atcp4 0 0 0 0 0 *.22 *.* CLOSED ANY 0x01FFFE7E ------- ------ 0 0 0 ---------------- 0 0 0 0 0 1073725440 1073725440 1220 cubic N/Atcp4 0 0 0 0 0 *.22 *.* CLOSED ANY 0x01FFFE7E ------- ------ 0 0 0 ---------------- 0 0 0 0 0 1073725440 1073725440 1220 cubic N/Atcp4 0 0 0 0 0 *.22 *.* CLOSED ANY 0x01FFFE7E ------- ------ 0 0 0 ---------------- 0 0 0 0 0 1073725440 1073725440 1220 cubic N/A