>[оверквотинг удален]
>> # uname -a
>> FreeBSD gate_mirvideo.mir-video.ru 9.2-RELEASE-p5 FreeBSD 9.2-RELEASE-p5 #1 r265947:
>> Fri May 16 11:02:47 UTC 2014 nops@gate.mir-video.ru:/usr/obj/usr/src/sys/ROUTER
>> amd64
>> Подскажите коллеги, куда можно еще заглянуть, чтобы эту беду исправить.
> Покажите вывод
>
> sockstat | grep ssh
>
> А потом в руки tcpdump и изучайте пакетики с 22 порта.# sockstat | grep ssh
nops sshd 89219 3 tcp4 192.168.4.1:22 192.168.0.222:49161
nops sshd 89219 4 stream -> ??
nops sshd 89219 6 stream -> /var/db/samba/winbindd_privileged/pipe
root sshd 89217 3 tcp4 192.168.4.1:22 192.168.0.222:49161
root sshd 89217 5 stream -> ??
root sshd 89217 6 stream -> /var/db/samba/winbindd_privileged/pipe
nops sshd 86624 3 tcp4 192.168.4.1:22 192.168.0.222:57458
nops sshd 86624 4 stream -> ??
nops sshd 86624 6 stream -> /var/db/samba/winbindd_privileged/pipe
root sshd 86622 3 tcp4 192.168.4.1:22 192.168.0.222:57458
root sshd 86622 5 stream -> ??
root sshd 86622 6 stream -> /var/db/samba/winbindd_privileged/pipe
root sshd 3650 3 tcp4 *:22 *:*
root sshd 3650 4 stream -> /var/db/samba/winbindd_privileged/pipe
И вот что TCPDUMP дал:
# tcpdump -i rl0 port 22
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on rl0, link-type EN10MB (Ethernet), capture size 65535 bytes
11:42:53.748888 IP Z.Z.Z.Z.52169 > X-X-X-X.vi-line.ru.22: Flags [S], seq 3626823898, win 65535, options [mss 1460,nop,wscale 5,nop,nop,TS val 713922765 ecr 0,sackOK,eol], length 0
11:42:54.749451 IP Z.Z.Z.Z.52169 > X-X-X-X.vi-line.ru.22: Flags [S], seq 3626823898, win 65535, options [mss 1460,nop,wscale 5,nop,nop,TS val 713923765 ecr 0,sackOK,eol], length 0
11:42:55.750491 IP Z.Z.Z.Z.52169 > X-X-X-X.vi-line.ru.22: Flags [S], seq 3626823898, win 65535, options [mss 1460,nop,wscale 5,nop,nop,TS val 713924765 ecr 0,sackOK,eol], length 0
11:42:56.752237 IP Z.Z.Z.Z.52169 > X-X-X-X.vi-line.ru.22: Flags [S], seq 3626823898, win 65535, options [mss 1460,nop,wscale 5,nop,nop,TS val 713925765 ecr 0,sackOK,eol], length 0
11:42:57.752784 IP Z.Z.Z.Z.52169 > X-X-X-X.vi-line.ru.22: Flags [S], seq 3626823898, win 65535, options [mss 1460,nop,wscale 5,nop,nop,TS val 713926765 ecr 0,sackOK,eol], length 0
11:42:58.758353 IP Z.Z.Z.Z.52169 > X-X-X-X.vi-line.ru.22: Flags [S], seq 3626823898, win 65535, options [mss 1460,nop,wscale 5,nop,nop,TS val 713927765 ecr 0,sackOK,eol], length 0
11:43:00.764915 IP Z.Z.Z.Z.52169 > X-X-X-X.vi-line.ru.22: Flags [S], seq 3626823898, win 65535, options [mss 1460,nop,wscale 5,nop,nop,TS val 713929765 ecr 0,sackOK,eol], length 0
11:43:04.790242 IP Z.Z.Z.Z.52169 > X-X-X-X.vi-line.ru.22: Flags [S], seq 3626823898, win 65535, options [mss 1460,sackOK,eol], length 0
11:43:12.802301 IP Z.Z.Z.Z.57201 > X-X-X-X.vi-line.ru.22: Flags [S], seq 3626823898, win 65535, options [mss 1460,sackOK,eol], length 0
^C
9 packets captured
9768 packets received by filter
0 packets dropped by kernel
Как бы пакеты прилетают, но вот что происходит дальше...
Еще есть вот такой вывод:
# tcpdump -v -i rl0 port 22
tcpdump: listening on rl0, link-type EN10MB (Ethernet), capture size 65535 bytes
11:46:19.243356 IP (tos 0x0, ttl 56, id 49883, offset 0, flags [DF], proto TCP (6), length 64)
Z.Z.Z.Z.60330 > Х-Х-Х-Х.vi-line.ru.22: Flags [S], cksum 0xe955 (correct), seq 857890313, win 65535, options [mss 1460,nop,wscale 5,nop,nop,TS val 714127469 ecr 0,sackOK,eol], length 0
# tcpdump -vv -i rl0 port 22
tcpdump: listening on rl0, link-type EN10MB (Ethernet), capture size 65535 bytes
11:46:30.307170 IP (tos 0x0, ttl 56, id 52294, offset 0, flags [DF], proto TCP (6), length 48)
Z.Z.Z.Z.60330 > Х-Х-Х-Х.vi-line.ru.22: Flags [S], cksum 0x1977 (correct), seq 857890313, win 65535, options [mss 1460,sackOK,eol], length 0
# tcpdump -vvv -i rl0 port 22
tcpdump: listening on rl0, link-type EN10MB (Ethernet), capture size 65535 bytes
11:47:41.685098 IP (tos 0x0, ttl 56, id 59475, offset 0, flags [DF], proto TCP (6), length 64)
Z.Z.Z.Z.60959 > X-X-X-X.vi-line.ru.22: Flags [S], cksum 0xb1f5 (correct), seq 3012678025, win 65535, options [mss 1460,nop,wscale 5,nop,nop,TS val 714209639 ecr 0,sackOK,eol], length 0