Monday, May 27, 2019

Having problems with connecting to server using windows 10 SSH

There is a server I connect to for work using putty and winscp. It connects properly without any issue all the time when using putty/winscp.

I wish to connect to this server using windows 10 command line ssh. However when I connect using CMD, I get the following error.

C:\Users\u###>ssh -v u###@####.###.####.com OpenSSH_for_Windows_7.6p1, LibreSSL 2.6.4 debug1: Reading configuration data C:\\Users\\u###/.ssh/config debug1: Reading configuration data __PROGRAMDATA__\\ssh/ssh_config debug1: Connecting to ####.###.####.com [##IP_ADDRESS##] port 22. debug1: Connection established. debug1: key_load_public: No such file or directory debug1: identity file C:\\Users\\u###/.ssh/id_rsa type -1 debug1: key_load_public: No such file or directory debug1: identity file C:\\Users\\u###/.ssh/id_rsa-cert type -1 debug1: key_load_public: No such file or directory debug1: identity file C:\\Users\\u###/.ssh/id_dsa type -1 debug1: key_load_public: No such file or directory debug1: identity file C:\\Users\\u###/.ssh/id_dsa-cert type -1 debug1: key_load_public: No such file or directory debug1: identity file C:\\Users\\u###/.ssh/id_ecdsa type -1 debug1: key_load_public: No such file or directory debug1: identity file C:\\Users\\u###/.ssh/id_ecdsa-cert type -1 debug1: key_load_public: No such file or directory debug1: identity file C:\\Users\\u###/.ssh/id_ed25519 type -1 debug1: key_load_public: No such file or directory debug1: identity file C:\\Users\\u###/.ssh/id_ed25519-cert type -1 debug1: Local version string SSH-2.0-OpenSSH_for_Windows_7.6 debug1: Remote protocol version 2.0, remote software version OpenSSH_7.4 debug1: match: OpenSSH_7.4 pat OpenSSH* compat 0x04000000 debug1: Authenticating to ####.###.####.com:22 as 'u###' debug1: SSH2_MSG_KEXINIT sent debug1: SSH2_MSG_KEXINIT received debug1: kex: algorithm: ################# debug1: kex: host key algorithm: ############# debug1: kex: server->client cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none debug1: kex: client->server cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none debug1: expecting SSH2_MSG_KEX_ECDH_REPLY debug1: Server host key: ############################################# debug1: Host '####.###.####.com' is known and matches the ECDSA host key. debug1: Found key in C:\\Users\\u###/.ssh/known_hosts:2 debug1: rekey after 134217728 blocks debug1: SSH2_MSG_NEWKEYS sent debug1: expecting SSH2_MSG_NEWKEYS debug1: SSH2_MSG_NEWKEYS received debug1: rekey after 134217728 blocks debug1: pubkey_prepare: ssh_get_authentication_socket: No such file or directory debug1: SSH2_MSG_EXT_INFO received debug1: kex_input_ext_info: ############### debug1: SSH2_MSG_SERVICE_ACCEPT received \S Kernel \r on an \m debug1: Authentications that can continue: publickey,gssapi-keyex,gssapi-with-mic debug1: Next authentication method: publickey debug1: Trying private key: C:\\Users\\u###/.ssh/id_rsa debug1: Trying private key: C:\\Users\\u###/.ssh/id_dsa debug1: Trying private key: C:\\Users\\u###/.ssh/id_ecdsa debug1: Trying private key: C:\\Users\\u###/.ssh/id_ed25519 debug1: No more authentication methods to try. u###@####.###.####.com: Permission denied (publickey,gssapi-keyex,gssapi-with-mic). 

What am I missing ?

The main goal why I am doing this is so that I can connect the server to VsCode and use its python debugger.



Migrating UniFi controllers

Hey guys,

I've been given the task to migrate some UniFi gear from a customer's controller into another controller, I however don't have much experience in terms of UniFi so I figured I'd ask here.

I have no Super Administrator access into the current controller so I can't use the backup/export site function to back up the site and use the migrate wizard to switch controllers. Is there any other reasonable way to do this while retaining PSKs, VLANs and everything that's configured already? It seems like a big hassle to have to re-do everything manually.

Any advice is appreciated.

Thanks!



are surge protectors bi-directional?

I'm just a computer nerd, ignorant of matters electrical and networking.

My question: are surge protectors bi-directional?

Motivation: Denver Colorado can get vigorous thunderstorms.

Wondering if lightning side flash could flow in through coax on a cable modem,

into the modem's surge protector, and upstream into the house circuit?

Overview: what I'm planning (details below):

1) Whole-house surge protector (type2 at panel).

2) Computer & network gear: surge protectors (maybe UPS later).

3) ethernet: Cable modem to switch isolation (fiber + media converter).

My main question is on (3), but I'd welcome any advice you can offer on my blind spots.

For (3) Cable modem, I'm wondering if lighting side-flash via coax something to worry about? (Comcast xfinity if it matters.)

I'll have the cable modem powered through a surge protector, which will be dowstream from the whole-house surge protector. Which got me wondering, are surge protectors bi-directional?

I've read that coax surge protectors don't do much, and may mess with the internet signal, so I'm planning on skipping that for now (I'm open on this point; I don't know enough to have an informed opinion).

Parts & Details:

whole-house surge protector:
I was browsing this article, seems like the Eaton CHSPT2ULTRA is a good unit.

wall plug surge protectors:
To get started, I'm putting APC P12U2 surge protectors on computer gear (laptop chargers, desktop, monitors). Basically everything that the computers physically connect to. Maybe uninterruptible power supplies later - I still need to research that.

ethernet:
Fiber isolation w/media converters, seems easier to get a new cable modem. For roughly $100 this seems like cheap insurance.



Sunday, May 26, 2019

Simple rack enclosure/mount

I'm looking for a simple enclose or wall/ceiling rack mount that'll hold a 1u HP DL360 G7 server. 4U Max. Queck specs: 27.25" deep, 35lbs. The ones I have come across are either not deep enough,or too large. Any direction would be appreciated.



Moronic Monday!

It's Monday, you've not yet had coffee and the week ahead is gonna suck. Lets open the floor for a weekly Stupid Questions Thread, so we can all ask those questions we're too embarassed to ask!

Post your question - stupid or otherwise - here to get an answer. Anyone can post a question and the community as a whole is invited and encouraged to provide an answer. Serious answers are not expected.



Would connecting my computer through both Ethernet and wifi improve my gaming experience?

I have two subscriptions to two ISPs but they're both kinda shit. Yesterday I discovered that I can connect my PC through ethernet to ISP1 and wifi to ISP2 to increase speed, and there are many articles that confirm this. But I can't find anything specific to gaming and lowering ping and packet loss.

Would windows use both connections for the same program (the game) or is it something closer to windows using the two connections to connect different programs (i.e chrome on ISP1 and and Teamspeak on ISP2)?



psuedowire/crossconnct vs. vxlan

I am behind the ball on this technology space and trying to rapidly catchup in order for an open project I have.

Given a mpls based ospf network, primarily PE and few to almost no P routers, why would you use vxlan versus pseudowire ?

Here is my thinking, and it is purely thinking after crashing on this over the last two days. I would like to hear from someone / anyone who has implemented this and/or supports it..

I am thinking pseudowire is a good fit for using the l2 vpn as a transit for a /30, where your CE type devices just use it for direct peering without terminating on the provide edge gear.

For vxlan, this use case is when you truly need to extend a layer2 vlan across network. I do get the mentality of let's do L3 to all the things to avoid issues with broadcast domain. However, once you do that - you really just converted your arp's and broadcast traffic to igmp multicast messages .. or even cooler are now using multi protocol bgp for layer2 and using bgp to share mac addresses instead of the default arp mechanism. - So what? You are still sending the data, every bit of it.

The only benefit I see is L2 not having a ttl and L3 does, therefore a spanning tree meltdown wont tank the bridge.

Given the state of pvrspt and a decent design, that's pretty unlikely in this day and age.

I feel like I am missing something, and need to be hit by a clue-by-4

Could someone please do so?



Quick question here please.

Hello everyone, I’ve read about cell phone tracking using three cell phone towers but one question remained in my head: how accurate is cell phone tracking using three cell phone towers? Is it within centimetres, meters or kilometres?



Elon Musk's - Starlink Network Explained

Hey,

found this cool animation of the routing behind the proposed Starlink satellite network.

Thought it would be cool for all us engineers to see.

https://www.youtube.com/watch?v=3479tkagiNo



Ethernet bypassing RADIUS authentication

Hi all,

I have a RADIUS server set up, and it works properly with wireless devices(meaning it requires authentication before connecting). However with wired devices, a device wired straight to the router can get access without any authentication whatsoever. I am using freeRADIUS, and the router is set up as a client. Is this a parameter I can change? Or does RADIUS not work with Ethernet?