gpt4 book ai didi

azure - ACS 中 Mesosphere 的 SSH 转发失败并显示 "administratively prohibited"

转载 作者:行者123 更新时间:2023-12-03 04:29:49 25 4
gpt4 key购买 nike

我刚刚按照描述的步骤 here 在 Azure 容器服务中创建了一个新的 Mesosphere 集群使用默认的template 。集群/资源已创建,我只想通过 ssh 转发连接到集群。连接已建立,但当我尝试在转发端口 80 上打开页面时,我收到 channel 2: open failed: 管理禁止:打开失败

这是详细的 ssh 日志:

sudo ssh -v -i ~/.ssh/id_rsa -L 80:localhost:80 -f -N       <a href="https://stackoverflow.com/cdn-cgi/l/email-protection" class="__cf_email__" data-cfemail="53322926213626203621133e2a2036212536213e343e277d3d3c21273b3626213c23367d303f3c26373223237d32292621367d303c3e" rel="noreferrer noopener nofollow">[email protected]</a> -p 2200
OpenSSH_6.9p1, LibreSSL 2.1.8
debug1: Reading configuration data /etc/ssh/ssh_config
debug1: /etc/ssh/ssh_config line 20: Applying options for *
debug1: /etc/ssh/ssh_config line 102: Applying options for *
debug1: Connecting to myservermgmt.northeurope.cloudapp.azure.com [52.178.215.121] port 2200.
debug1: Connection established.
debug1: permanently_set_uid: 0/0
debug1: identity file /Users/me/.ssh/id_rsa type 1
debug1: key_load_public: No such file or directory
debug1: identity file /Users/me/.ssh/id_rsa-cert type -1
debug1: Enabling compatibility mode for protocol 2.0
debug1: Local version string SSH-2.0-OpenSSH_6.9
debug1: Remote protocol version 2.0, remote software version OpenSSH_7.2p2 Ubuntu-4ubuntu1
debug1: match: OpenSSH_7.2p2 Ubuntu-4ubuntu1 pat OpenSSH* compat 0x04000000
debug1: Authenticating to myservermgmt.northeurope.cloudapp.azure.com:2200 as 'azureuser'
debug1: SSH2_MSG_KEXINIT sent
debug1: SSH2_MSG_KEXINIT received
debug1: kex: server->client <a href="https://stackoverflow.com/cdn-cgi/l/email-protection" class="__cf_email__" data-cfemail="8cefe4edefe4edbebca1fce3e0f5bdbfbcb9cce3fce9e2ffffe4a2efe3e1" rel="noreferrer noopener nofollow">[email protected]</a> <implicit> none
debug1: kex: client->server <a href="https://stackoverflow.com/cdn-cgi/l/email-protection" class="__cf_email__" data-cfemail="98fbf0f9fbf0f9aaa8b5e8f7f4e1a9aba8add8f7e8fdf6ebebf0b6fbf7f5" rel="noreferrer noopener nofollow">[email protected]</a> <implicit> none
debug1: expecting SSH2_MSG_KEX_ECDH_REPLY
debug1: Server host key: ecdsa-sha2-nistp256 SHA256:ZMD6A/rz3qWsn2V6yQyeg3kG8vFtweDc72oAZCLo9xs
debug1: Host '[myservermgmt.northeurope.cloudapp.azure.com]:2200' is known and matches the ECDSA host key.
debug1: Found key in /var/root/.ssh/known_hosts:2
debug1: SSH2_MSG_NEWKEYS sent
debug1: expecting SSH2_MSG_NEWKEYS
debug1: SSH2_MSG_NEWKEYS received
debug1: SSH2_MSG_SERVICE_REQUEST sent
debug1: SSH2_MSG_SERVICE_ACCEPT received
debug1: Authentications that can continue: publickey,password
debug1: Next authentication method: publickey
debug1: Offering RSA public key: /Users/me/.ssh/id_rsa
debug1: Server accepts key: pkalg ssh-rsa blen 279
debug1: Authentication succeeded (publickey).
Authenticated to myservicemgmt.northeurope.cloudapp.azure.com ([52.178.215.121]:2200).
debug1: Local connections to LOCALHOST:80 forwarded to remote address localhost:80
debug1: Local forwarding listening on ::1 port 80.
debug1: channel 0: new [port listener]
debug1: Local forwarding listening on 127.0.0.1 port 80.
debug1: channel 1: new [port listener]
debug1: Requesting <a href="https://stackoverflow.com/cdn-cgi/l/email-protection" class="__cf_email__" data-cfemail="d0bebffdbdbfa2b5fda3b5a3a3b9bfbea390bfa0b5bea3a3b8feb3bfbd" rel="noreferrer noopener nofollow">[email protected]</a>
debug1: forking to background
debug1: Entering interactive session.
debug1: client_input_global_request: rtype <a href="https://stackoverflow.com/cdn-cgi/l/email-protection" class="__cf_email__" data-cfemail="85edeaf6f1eee0fcf6a8b5b5c5eaf5e0ebf6f6edabe6eae8" rel="noreferrer noopener nofollow">[email protected]</a> want_reply 0
debug1: Connection to port 80 forwarding to localhost port 80 requested.
debug1: channel 2: new [direct-tcpip]
channel 2: open failed: administratively prohibited: open failed
debug1: channel 2: free: direct-tcpip: listening port 80 for localhost port 80, connect from 127.0.0.1 port 55718 to 127.0.0.1 port 80, nchannels 3
debug1: Connection to port 80 forwarding to localhost port 80 requested.

据我所知,这可能意味着服务器上未启用PermitTunnel。由于 ssh 隧道在我的计算机上用于其他目的,我想知道 ACS 中是否有任何需要配置的内容?我已经尝试通过 ssh 直接进入 DCOS master,但没有成功。

感谢任何帮助。

最佳答案

AFAIK this could mean `PermitTunnel is not enabled on the server.

不是,是目标服务器的/etc/ssh/sshd_config中的AllowTcpForwarding。或 PermitOpen 指令。

另请注意,如果您不是在 root 下运行或没有特定权限,则无法在系统上绑定(bind)特权端口。

关于azure - ACS 中 Mesosphere 的 SSH 转发失败并显示 "administratively prohibited",我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/38534946/

25 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com