SSH Server Slow/Lagged/Delayed Login Response

This is really something the SSH Server developers should consider.  The cause of this annoyance is because of failed DNS lookups on your IP address, which is especially common for many dedicated/col-located servers and also computers on internal NAT/private networks.

The chances are this is the cause of your SSH Slow/Delayed Login problems.

The easy solution to SSH Login Problems

Edit /etc/ssh/sshd_config

Add this line to disable reverse DNS lookups when someone is logging into your SSH Server:

UseDNS no

*Don't forget to restart your SSH daemon for the change to take effect!

It would make sense for this option to be disabled by default, especially considering that someone could have a fake or invalid reverse DNS which makes it impossible to find who was really logged in or trying to login.

The SSH daemon should not initially due any reverse DNS or at least allow the login process to continue and try a few more times during the session to find the reverse DNS if it must.

Another symptom aside from it being slow is if you debug the SSH client and see things freeze here:

debug1: SSH2_MSG_SERVICE_ACCEPT received

The problem will be solved once you apply "UseDNS no" to you sshd_confdig and restart SSH.


Tags:

ssh, server, lagged, delayed, login, responsethis, developers, annoyance, dns, lookups, ip, dedicated, col, located, servers, nat, networks, edit, etc, sshd_config, disable, logging, usedns, restart, daemon, disabled, default, invalid, logged, initially, symptom, debug, _msg_service_accept, quot, sshd_confdig,

Latest Articles

  • Proxmox How To Purge Ceph
  • VMWare ESXi/VSphere Disable Balloon Segfault in Services Solution
  • Apache Linux Debian Ubuntu Container how to manually restart without killing
  • Docker enable UTF8 in Container to stop seeing gibberish ? characters
  • Debian 8 How To Use Apt Update Archive sources.list
  • Debian Live CD Password
  • Forbidden You don't have permission to access this resource. [authz_core:error] [pid 338:tid 338] [client 1.2.3.4:55046] AH01630: client denied by server configuration:
  • The client needs a new connection for this request as the requested host name does not match the Server Name Indication (SNI) in use for this connection.
  • Asterisk RTP/audio not working in either direction in Docker NAT with a NAT client
  • dovecot: imap(root@localhost)<3702>: Error: Mailbox INBOX: mmap(size=352609044) failed with file /var/spool/mail/root/Maildir/dovecot.index.cache: Cannot allocate memory
  • Asterisk cannot find soundfile file.c:824 ast_openstream_full: File for-tech-support does not exist in any format
  • Apache Error solution - mktemp: failed to create directory via template '/var/lock/apache2.XXXXXXXXXX': No such file or directory
  • sysctl settings to reduce buffers and caches in Linux
  • Find /dev/sd block device of ata device - ata6: SATA link up 1.5 Gbps (SStatus 113 SControl 310) ata6.00: qc timeout (cmd 0xec) ata6.00: failed to IDENTIFY (I/O error, err_mask=0x4) ata6.00: revalidation failed (errno=-5)
  • Stuttering Audio on VOIP phones when first answering a call slow and fast audio
  • How to distribute the Microsoft VC Visual Studio Redistributable Files On Your Own
  • Nvidia video resolution and codec encode decode support matrix eg. h264 4k h265 HEVC VP9 Card List from GTX, RTX, Quadro
  • Japan and China ping time observations
  • ffmpeg convert to another format eg h265 to h264
  • Apache stop bots and hackers by using forensic logging.