Solved

intermitent SSH connection to Cisco Router

Posted on 2011-02-25
10
798 Views
Last Modified: 2012-05-11
Hi Experts,

I'm currently experiencing a very weird thing happening on my cisco router 3925. It seems that when I try to connect to the router via SSH, sometimes it connects and sometimes it just times out. Anyone out there experience a similar problem? Thanks in advance.
0
Comment
Question by:ffleisma
  • 3
  • 3
  • 2
  • +2
10 Comments
 
LVL 24

Expert Comment

by:rfc1180
ID: 34984870
Can you post your config?
0
 
LVL 9

Author Comment

by:ffleisma
ID: 34984932
no i can't, its for my work, i know it won't be much help if i can't post the config. i posted the question just ot get an idea on where i could start troubleshooting this problem.
0
 
LVL 79

Accepted Solution

by:
lrmoore earned 100 total points
ID: 34984971
>sometimes it connects and sometimes it just times out
Usually, if it connects at all, the configuration is correct.
During the times that it times out, the router could be CPU bound and simply cannot accept incomming connections. There could be a memory leak bug in the current IOS version...
0
Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

 
LVL 24

Assisted Solution

by:rfc1180
rfc1180 earned 200 total points
ID: 34985054
do you have one internet connection or dual Internet (asymetrical routing, or routing convergance issues?).
An issue end to end from you and the router (Packet loss, high latency)
Congested link, etc.
0
 
LVL 10

Assisted Solution

by:lanboyo
lanboyo earned 100 total points
ID: 34985181
When you say times out, do you mean that it does not connect to the router  ( tecp timeout) or it connects but you can't enter your password?

When you try to connect to the router and you time out you should do a traceroute and ping the address you use to ssh to.

Keep a running ping in a window and keep trying to connect. See if the results change when you time out.

If your network pings and traceroutes do not change, then configure the router to log debug  messages to flash (logging debug ), and turn on this debug command:

debug ip ssh client

Check the timestamps and see it the router sees the incoming ssh sessions.

0
 
LVL 9

Author Comment

by:ffleisma
ID: 34985271
one thing is for sure there are no packet loss as i check the counters in the interfaces, it shows 0 for all errors. this is a private IP circuit with dual-homed 3xT1 circuit.

i also don't think it would be an ios problem as we have already installed more than 500 sites using the same ios and this weird problem only exist for this one site.

management IP is pingable even at a continuous ping it doesn't drop.

it doesn't even proceed with asking me for a password, aaa tacacs is used for authentication. when i hit ssh -l username ip-address, it just comes as "blank" it doesn'st show disconnect, timeout or anything. nothing just happens and next line is blank.

thanks for the ideas guys, how about the CPU bound problem you mentioned? how can i check this?
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 34985284
As soon as you can get in, check
show proc cpu hist
Shows you a little graph of past hour, 24 hours, 72 hours and you can see if there are spikes of high utilization.
0
 
LVL 9

Author Comment

by:ffleisma
ID: 34987218
yes i did that already and it didn't show any high utilization or spikes. for now im scheduling maintenance and i'll probably run debug commands, any suggestion on what debug commands that could help me?
0
 
LVL 24

Assisted Solution

by:rfc1180
rfc1180 earned 200 total points
ID: 34988316
I would also include into your troubleshooting a packet capture of the issue you are having; what is happening at the packet level. Are the 2 endpoints completing the 3way-hand shake, what else is happening after the 3-way handshake if it is succeeding.

debug ip tcp packet x.x.x.x (host that you are trying to connect to)
debug ip ssh
debug arp
debug ip packet (Be careful with this one, I would recommend that you setup an access-list and specify only the hosts you will be troubleshooting
debug ip routing (This will monitor the routing table to check for flapping routes)

Run each debug separately.

Billy
0
 
LVL 17

Assisted Solution

by:MAG03
MAG03 earned 100 total points
ID: 34991416
is the "ip ssh timeout" configured?  if this value is set too low you wont be able to type in your password before the session times out.

ip ssh timeout detects issues in the negotiation stage

exec-timeout detects user inactivity
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

#Citrix #Citrix Netscaler #HTTP Compression #Load Balance
Most of the applications these days are on Cloud. Cloud is ubiquitous with many service providers in the market. Since it has many benefits such as cost reduction, software updates, remote access, disaster recovery and much more.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

803 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question