Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
faq:tcpip [2010/02/24 16:50] – digitalman | faq:tcpip [2020/06/01 21:33] (current) – [Rebind] TIME WAIT or CLOSE WAIT - both are indications of the same problem digital man | ||
---|---|---|---|
Line 1: | Line 1: | ||
- | ====== TCP/IP ====== | + | ====== TCP/ |
Answers to Frequently Asked Questions regarding Synchronet and TCP/IP (the Internet protocol suite). | Answers to Frequently Asked Questions regarding Synchronet and TCP/IP (the Internet protocol suite). | ||
Line 11: | Line 11: | ||
* [[# | * [[# | ||
* [[# | * [[# | ||
+ | * [[# | ||
* [[#bind|Why do some or all of my servers get bind errors when starting or recycling]]? | * [[#bind|Why do some or all of my servers get bind errors when starting or recycling]]? | ||
* [[# | * [[# | ||
+ | * [[# | ||
+ | * [[# | ||
+ | * [[# | ||
===== Ports ===== | ===== Ports ===== | ||
- | **Question: | + | :?: **Question: |
What inbound ports do I need to open in my firewall? | What inbound ports do I need to open in my firewall? | ||
- | **Answer: | + | :!: **Answer: |
Depends on which Synchronet servers and services you wish to make available to Internet clients and which ports you have configured those servers and services to listen on. | Depends on which Synchronet servers and services you wish to make available to Internet clients and which ports you have configured those servers and services to listen on. | ||
Line 27: | Line 31: | ||
|Telnet | |Telnet | ||
|SSH |22 |- |For SecureShell logins (recommended)| | |SSH |22 |- |For SecureShell logins (recommended)| | ||
- | |RLogin | + | |RLogin |
- | |SMTP | + | |SMTP |
+ | |Submission | ||
+ | |Submission/ | ||
|POP3 | |POP3 | ||
+ | |POP3/ | ||
|FTP |21 |- |Allows access to the BBS file/ | |FTP |21 |- |Allows access to the BBS file/ | ||
|HTTP | |HTTP | ||
+ | |HTTPS | ||
|NNTP | |NNTP | ||
|Gopher | |Gopher | ||
|IRC |6667 |- |Allows Internet Relay Chat (IRC) clients to connect to your BBS| | |IRC |6667 |- |Allows Internet Relay Chat (IRC) clients to connect to your BBS| | ||
- | |Finger | + | |Finger |
- | |SYSTAT | + | |SYSTAT |
- | |QOTD | + | |MSP |18 | |Allows incoming |
- | |MSP |18 |18 |Allows incoming inter-BBS instant messages | + | |WS |
+ | |WSS |11235 | ||
Enabling connectivity to Synchronet through your firewall is no different than enabling connectivity to any other TCP/IP server. Follow your firewall documentation for forwarding or opening ports for TCP/IP servers located " | Enabling connectivity to Synchronet through your firewall is no different than enabling connectivity to any other TCP/IP server. Follow your firewall documentation for forwarding or opening ports for TCP/IP servers located " | ||
+ | |||
+ | [[http:// | ||
===== Private IP ===== | ===== Private IP ===== | ||
- | **Question: | + | :?: **Question: |
How come my friends can't connect to my BBS at my 192.168.x.x, | How come my friends can't connect to my BBS at my 192.168.x.x, | ||
- | **Answer: | + | :!: **Answer: |
- | The IP address ranges listed above are reserved for use in private networks and are not publicly addressable from the Internet. See [[http:// | + | The IP address ranges listed above are reserved for use in private networks and are not publicly addressable from the Internet. See [[rfc>1918|this document]] for technical details. |
- | You do not want to advertise this IP address to the public since it is useless to anyone outside of your own private/ | + | You do not want to advertise this IP address to the public since it is useless to anyone outside of your own private/ |
===== Public IP ===== | ===== Public IP ===== | ||
- | **Question: | + | :?: **Question: |
What is my public IP address? | What is my public IP address? | ||
- | **Answer: | + | :!: **Answer: |
If you need to know your public IP address, you can usually query your router/ | If you need to know your public IP address, you can usually query your router/ | ||
If you use a [[module: | If you use a [[module: | ||
+ | |||
+ | Another way that will accurately scan and diagnose your IP connectivity is [[http:// | ||
+ | |||
===== Relay Mail ===== | ===== Relay Mail ===== | ||
- | **Question: | + | :?: **Question: |
Why can't I relay Internet e-mail through my BBS? | Why can't I relay Internet e-mail through my BBS? | ||
- | **Answer: | + | :!: **Answer: |
Indications of this problem include error messages in your e-mail client similar to the following: | Indications of this problem include error messages in your e-mail client similar to the following: | ||
553 Relaying through this server requires authentication. Please authenticate before sending. | 553 Relaying through this server requires authentication. Please authenticate before sending. | ||
Line 81: | Line 95: | ||
You can allow specific hosts or users to relay e-mail through your mail server by either: | You can allow specific hosts or users to relay e-mail through your mail server by either: | ||
- | Entering the sending host's IP address or hostname in your [[config: | + | Entering the sending host's IP address or hostname in your '' |
This file may be edited with the SBBSCTRL: | This file may be edited with the SBBSCTRL: | ||
Line 88: | Line 102: | ||
Use SMTP authentication: | Use SMTP authentication: | ||
Enable the mail server configuration option to allow authenticated users to relay mail. | Enable the mail server configuration option to allow authenticated users to relay mail. | ||
- | This can be done by adding '' | + | This can be done by adding '' |
Or, if using SBBSCTRL, checking the "Allow Authenticated Users to Relay Mail" checkbox on the SMTP tab of the Mail Server Configuration dialog. | Or, if using SBBSCTRL, checking the "Allow Authenticated Users to Relay Mail" checkbox on the SMTP tab of the Mail Server Configuration dialog. | ||
Line 100: | Line 114: | ||
===== Send Mail ===== | ===== Send Mail ===== | ||
- | **Question: | + | :?: **Question: |
Why can't I send Internet e-mail from my BBS? | Why can't I send Internet e-mail from my BBS? | ||
- | **Answer: | + | :!: **Answer: |
You must have the Synchronet SendMail thread enabled in your Synchronet Mail Server configuration. | You must have the Synchronet SendMail thread enabled in your Synchronet Mail Server configuration. | ||
If you do not see the following message in your Synchronet Mail Server window/log output when the server is started or recycled: | If you do not see the following message in your Synchronet Mail Server window/log output when the server is started or recycled: | ||
Line 136: | Line 150: | ||
If your ISP's mail server only allows e-mail to be sent from '' | If your ISP's mail server only allows e-mail to be sent from '' | ||
+ | |||
+ | One possible solution if **outbound** TCP port 25 is blocked by your ISP is to use an SMTP relay server which accepts connections on another TCP port (say, 587) and will then relay your mail to the destination mail server on port 25. If you wish, you can [[howto: | ||
You have your mail server configured to use an external "Relay Server", | You have your mail server configured to use an external "Relay Server", | ||
Line 147: | Line 163: | ||
0000 !Delivery attempt #1 FAILED (somehost.org replied with: "553 Authentication required." | 0000 !Delivery attempt #1 FAILED (somehost.org replied with: "553 Authentication required." | ||
- | Synchronet v3.12+ supports the Plain, Login, and CRAM-MD5 methods of SMTP authentication when relaying mail through an external relay server. To enable SMTP authentication when relaying, add one of the '' | + | Synchronet v3.12+ supports the Plain, Login, and CRAM-MD5 methods of SMTP authentication when relaying mail through an external relay server. To enable SMTP authentication when relaying, add one of the '' |
You have a message in your outbound e-mail queue that is flagged as 'in transit' | You have a message in your outbound e-mail queue that is flagged as 'in transit' | ||
Line 155: | Line 171: | ||
This condition can occur if the Synchronet SendMail thread is terminated unexpectedly while in the process of attempting the delivery an outbound e-mail message. The 'in transit' | This condition can occur if the Synchronet SendMail thread is terminated unexpectedly while in the process of attempting the delivery an outbound e-mail message. The 'in transit' | ||
- | If you only have one instance of the Synchronet SendMail thread active (the usual scenario), you can eliminate this problem by adding '' | + | If you only have one instance of the Synchronet SendMail thread active (the usual scenario), you can eliminate this problem by adding '' |
In general, you need to check your Synchronet Mail Server window/log output for details about why Internet e-mail delivery attempts may be failing. | In general, you need to check your Synchronet Mail Server window/log output for details about why Internet e-mail delivery attempts may be failing. | ||
===== Receive Mail ===== | ===== Receive Mail ===== | ||
- | **Question: | + | :?: **Question: |
Why can't my BBS receive Internet e-mail? | Why can't my BBS receive Internet e-mail? | ||
- | **Answer: | + | :!: **Answer: |
- | You must have the Synchronet SMTP (mail) server running and listening for incoming connections on TCP port 25 (the standard SMTP port). You (or a friend) can test this basic connectivity by attempting to Telnet to port 25 (instead of port 23) at your BBS's hostname or public IP address from a remote location on the Internet. The remote Telnet client should see a successful connection and a text message similar to the following: | + | You must have the Synchronet SMTP (mail) server running and listening for incoming connections on TCP port 25 (the standard SMTP port). You (or a friend) can test this basic connectivity by attempting to Telnet to port 25 (instead of port 23) at your BBS's hostname or [[#public IP]] address from a remote location on the Internet. The remote Telnet client should see a successful connection and a text message similar to the following: |
220 bbs.synchro.net Synchronet SMTP Server 1.362-Win32 Ready | 220 bbs.synchro.net Synchronet SMTP Server 1.362-Win32 Ready | ||
Line 173: | Line 189: | ||
===== FTP Connect ===== | ===== FTP Connect ===== | ||
- | **Question: | + | :?: **Question: |
Why can't users connect to my FTP server? | Why can't users connect to my FTP server? | ||
- | **Answer: | + | :!: **Answer: |
You must have the Synchronet FTP server running and listening for incoming connections on TCP port 21 (the standard FTP port). See the previous answer about methods of testing this basic connectivity using a remote Telnet client. | You must have the Synchronet FTP server running and listening for incoming connections on TCP port 21 (the standard FTP port). See the previous answer about methods of testing this basic connectivity using a remote Telnet client. | ||
If your FTP server window/log indicates an accepted FTP connection, then it's not a connectivity problem and probably a login failure. | If your FTP server window/log indicates an accepted FTP connection, then it's not a connectivity problem and probably a login failure. | ||
- | FTP sessions require a login. If you have not created a Guest account for your BBS, then the FTP server will not allow Annonymous logins (most web browsers, for example, will attempt to login anonymously by default). If this is the problem, then either create a Guest account | + | FTP sessions require a login. If you have not created a [[:access:#Guest]] account for your BBS, then the FTP server will not allow Annonymous logins (most web browsers, for example, will attempt to login anonymously by default). If this is the problem, then either |
===== FTP NAT ===== | ===== FTP NAT ===== | ||
- | **Question: | + | :?: **Question: |
Why do FTP clients lock-up or time-out when listing directories or downloading files from my FTP server? | Why do FTP clients lock-up or time-out when listing directories or downloading files from my FTP server? | ||
- | **Answer: | + | :!: **Answer: |
- | Your BBS computer is probably behind a Network Address Translator ([[http:// | + | Your BBS computer is probably behind a Network Address Translator ([[rfc>1631|NAT]]). NAT functionality is typically built into router/ |
[[http:// | [[http:// | ||
- | :!: Note: Most web browsers | + | **Note**: Most web browsers use //passive// FTP transfer mode by default, though this may be configurable. |
- | :!: Note: Some FTP clients (e.g. the Windows command-line FTP client, '' | + | **Note**: Some FTP clients (e.g. the Windows command-line FTP client, '' |
- | Enabling the logging of FTP data channel activity can help diagnose these kinds of problems. This can be done by adding the DEBUG_DATA option to the Options value in the [FTP] section of your [[config: | + | Enabling the logging of FTP data channel activity can help diagnose these kinds of problems. This can be done by adding the '' |
- | + | ||
- | If you're having problems with passive transfers and you're seeing | + | |
- | !UNSUPPORTED COMMAND from username: ' | + | |
- | in your FTP server log/window output, you're probably using an //SMC Barricade// router (see [[http:// | + | |
If you're having problems with passive (PASV) transfers through your NAT/ | If you're having problems with passive (PASV) transfers through your NAT/ | ||
- | If the remote client is attempting to connect to your [[#private IP]] address (your NAT device isn't translating the PASV response from the FTP server) and you have a static [[#public IP]] address, you can work-around this limitation of your NAT device by using the '' | + | If the remote client is attempting to connect to your [[#private IP]] address (your NAT device isn't translating the PASV response from the FTP server) and you have a static [[#public IP]] address, you can work-around this limitation of your NAT device by using the '' |
This problem can be identified (on the client) by finding a comma-separated [[#private IP]] address in the PASV response received from the FTP server (in response to a directory or file transfer request from the client). | This problem can be identified (on the client) by finding a comma-separated [[#private IP]] address in the PASV response received from the FTP server (in response to a directory or file transfer request from the client). | ||
Line 223: | Line 235: | ||
Use an FTP client that supports passive mode and can display all the responses received-from the FTP server to help identify this particular problem. The FTP client must be running on a system outside your private network, so you may need a friend to assist you with this. | Use an FTP client that supports passive mode and can display all the responses received-from the FTP server to help identify this particular problem. The FTP client must be running on a system outside your private network, so you may need a friend to assist you with this. | ||
- | If you have a dynamically-assigned IP address (via DHCP), then your IP address may change at some point, so setting the '' | + | If you have a dynamically-assigned IP address (via DHCP), then your IP address may change at some point, so setting the '' |
- | If your firewall cannot dynamically open/ | + | If your firewall cannot dynamically open/ |
+ | |||
+ | ===== FTP HTML ===== | ||
+ | :?: **Question: | ||
+ | Why will a web browser not (no longer) render the HTML content sent by the Synchronet FTP Server (i.e. '' | ||
+ | |||
+ | :!: **Answer: | ||
+ | For security reasons, modern web browsers (e.g. Google Chrome) have stopped rendering HTML content served by protocols other than HTTP or HTTPS. | ||
+ | * [[https:// | ||
+ | |||
+ | Some web browsers (e.g. Microsoft Edge) are removing FTP support altogether. | ||
+ | * [[https:// | ||
===== Bind ===== | ===== Bind ===== | ||
- | **Question: | + | :?: **Question: |
Why do some or all of my servers get bind errors when starting or recycling? | Why do some or all of my servers get bind errors when starting or recycling? | ||
- | **Answer: | + | |
+ | :!: **Answer: | ||
If you're getting bind errors when first starting up one or more Synchronet servers, similar to the following: | If you're getting bind errors when first starting up one or more Synchronet servers, similar to the following: | ||
0420 !ERROR 48 binding FTP Server socket to port 21 | 0420 !ERROR 48 binding FTP Server socket to port 21 | ||
- | This usually means you have another TCP/IP server on your system that is already bound to (and is presumably already listening for incoming connections on) this port. This could be a pre-existing instance of Synchronet or any other Telnet/ | + | **Note: |
+ | On Unix-like systems, the error number | ||
- | If you're running a Unix-like operating system (not Windows) and get bind errors only when recycling servers, this is most likely because a TCP session is stuck in a '' | + | This usually means you have another TCP/IP server on your system that is already bound to (and is presumably already listening for incoming connections on) this port. This could be a pre-existing instance of Synchronet or any other Telnet/ |
- | REUSEADDR 1 | + | |
- | Or, if running Synchronet v3.13b or later, your [[config: | + | :!: **Answer: |
+ | If you're getting bind errors when first starting up one or more Synchronet servers, similar to the following: | ||
+ | 0003 !ERROR 13 binding Web Server socket to port 80 | ||
+ | |||
+ | Error '' | ||
+ | This error upon binding usually means that you're running Synchronet as non-privileged user account (e.g. not ' | ||
+ | |||
+ | ==== Rebind ==== | ||
+ | :!: **Answer: | ||
+ | If you're running a Unix-like operating system (not Windows) and get bind errors | ||
+ | sbbs: term 0001 !ERROR 98 binding Telnet Server socket to port 23 | ||
+ | sbbs: term 0001 Will retry in 15 seconds (1 of 2) | ||
+ | |||
+ | ... this is most likely because a TCP session is stuck in a TCP "TIME WAIT" or "CLOSE WAIT" | ||
REUSEADDR=1 | REUSEADDR=1 | ||
+ | |||
===== Bandwidth ===== | ===== Bandwidth ===== | ||
- | **Question: | + | :?: **Question: |
How many nodes/ | How many nodes/ | ||
- | **Answer: | + | :!: **Answer: |
Depends on what those clients will be doing while connected. Here are some facts to consider: | Depends on what those clients will be doing while connected. Here are some facts to consider: | ||
Line 269: | Line 308: | ||
If you have a 256Kbps upstream channel, for example, you could support four or five simultaneous " | If you have a 256Kbps upstream channel, for example, you could support four or five simultaneous " | ||
+ | ===== Block Hackers ===== | ||
+ | :?: **Question: | ||
+ | Can Synchronet automatically block the IP address of hackers/ | ||
+ | |||
+ | :!: **Answer: | ||
+ | Yes, see [[howto: | ||
+ | |||
+ | ===== SSH Algo ===== | ||
+ | :?: **Question: | ||
+ | Why do some SSH clients (e.g. [[http:// | ||
+ | |||
+ | :!: **Answer: | ||
+ | SSH supports a variety of cryptographic algorithms for encryption (privacy), integrity (mac) and authentication (key-exchange). As stronger algorithms are introduced, older (less-strong) algorithms are deprecated. As a result, when using a newer version of any SSH client (especially OpenSSH), it may fail to connect to SSH servers which only support less-than-the-strongest (newest) algorithms. There is no permanent solution to this issue as cryptographic algorithms are constantly improving (becoming stronger) and older (weaker) algorithms are going out of favor. | ||
+ | |||
+ | |||
+ | ==== SSH Cipher Algo ==== | ||
+ | |||
+ | Should be fixed as of Fri Feb 14 07:37:04 2020 UTC. aes128-ctr and aes256-ctr support was added. | ||
+ | |||
+ | Example: | ||
+ | $ ssh vert.synchro.net | ||
+ | Unable to negotiate with vert.synchro.net port 22: no matching cipher found. Their offer: aes128-cbc, | ||
+ | | ||
+ | Workarounds for OpenSSH: | ||
+ | |||
+ | $ ssh -c aes128-cbc user@yourbbs.com | ||
+ | | ||
+ | or in the '' | ||
+ | |||
+ | Host yourbbs.com | ||
+ | Ciphers aes128-cbc | ||
+ | | ||
+ | ==== SSH Kex Algo ==== | ||
+ | |||
+ | Should be fixed as of Mon Jun 3 22:21:15 2019 UTC. diffie-hellman-group-exchange-sha256 and diffie-hellman-group14-sha256 support was added. | ||
+ | |||
+ | Example: | ||
+ | $ ssh vert.synchro.net | ||
+ | Received disconnect from 71.95.196.34: | ||
+ | | ||
+ | or: | ||
+ | Unable to negotiate with legacyhost: no matching key exchange method found. | ||
+ | Their offer: diffie-hellman-group1-sha1 | ||
+ | |||
+ | From the OpenSSH [[http:// | ||
+ | > OpenSSH implements all of the cryptographic algorithms needed for compatibility with standards-compliant SSH implementations, | ||
+ | |||
+ | Workarounds for OpenSSH: | ||
+ | |||
+ | $ ssh -oKexAlgorithms=+diffie-hellman-group1-sha1 user@yourbbs.com | ||
+ | |||
+ | or in the '' | ||
+ | |||
+ | Host yourbbs.com | ||
+ | KexAlgorithms diffie-hellman-group1-sha1 | ||
+ | | ||
+ | **Note:** | ||
+ | If you created this file to work-around the cryptlib v3.4.2 compatibility issue, you will need to remove this file or modify it after updating to cryptlib v3.4.4 | ||
+ | |||
+ | or in the '' | ||
+ | |||
+ | Host yourbbs.com | ||
+ | KexAlgorithms +diffie-hellman-group1-sha1 | ||
+ | |||
+ | Note: Run '' | ||
+ | |||
+ | ==== SSH MAC Algo ==== | ||
+ | |||
+ | Should be fixed as of Mon Jun 3 22:21:15 2019 UTC. hmac-sha2-256 support was added. | ||
+ | |||
+ | Another observed problem is with the negotiated Message Authentication Code (MAC) algorithm. | ||
+ | |||
+ | Workaround for OpenSSH (reported by nelgin): | ||
+ | |||
+ | $ ssh -m hmac-md5 user@yourbbs.com | ||
+ | |||
+ | ===== SSH Session Key ===== | ||
+ | :?: **Question: | ||
+ | How do I resolve the following terminal server SSH error? | ||
+ | |||
+ | ' | ||
+ | |||
+ | :!: **Answer: | ||
+ | Rename/move or delete your '' | ||
+ | |||
+ | If you're using TLS for your other [[server: | ||
+ | |||
+ | These files ('' | ||
===== See Also ===== | ===== See Also ===== | ||
- | * [[:faq:|faq index]] | + | * [[:server:|Servers]] |
+ | * [[: | ||
+ | * [[:faq: | ||
+ | {{tag> |