2016-07-22 61 views
0

我剛剛在遵循here使用默認template描述的步驟的Azure容器服務中創建了一個新的Mesosphere羣集。羣集/資源已創建,我只是想通過ssh轉發連接到羣集。建立連接,但是當我嘗試轉發端口80我得到channel 2: open failed: administratively prohibited: open failedACS中Mesosphere的SSH轉發失敗,導致「管理禁止」

上打開一個頁面下面是詳細ssh日誌:

sudo ssh -v -i ~/.ssh/id_rsa -L 80:localhost:80 -f -N  [email protected] -p 2200 
OpenSSH_6.9p1, LibreSSL 2.1.8 
debug1: Reading configuration data /etc/ssh/ssh_config 
debug1: /etc/ssh/ssh_config line 20: Applying options for * 
debug1: /etc/ssh/ssh_config line 102: Applying options for * 
debug1: Connecting to myservermgmt.northeurope.cloudapp.azure.com [52.178.215.121] port 2200. 
debug1: Connection established. 
debug1: permanently_set_uid: 0/0 
debug1: identity file /Users/me/.ssh/id_rsa type 1 
debug1: key_load_public: No such file or directory 
debug1: identity file /Users/me/.ssh/id_rsa-cert type -1 
debug1: Enabling compatibility mode for protocol 2.0 
debug1: Local version string SSH-2.0-OpenSSH_6.9 
debug1: Remote protocol version 2.0, remote software version OpenSSH_7.2p2 Ubuntu-4ubuntu1 
debug1: match: OpenSSH_7.2p2 Ubuntu-4ubuntu1 pat OpenSSH* compat 0x04000000 
debug1: Authenticating to myservermgmt.northeurope.cloudapp.azure.com:2200 as 'azureuser' 
debug1: SSH2_MSG_KEXINIT sent 
debug1: SSH2_MSG_KEXINIT received 
debug1: kex: server->client [email protected] <implicit> none 
debug1: kex: client->server [email protected] <implicit> none 
debug1: expecting SSH2_MSG_KEX_ECDH_REPLY 
debug1: Server host key: ecdsa-sha2-nistp256 SHA256:ZMD6A/rz3qWsn2V6yQyeg3kG8vFtweDc72oAZCLo9xs 
debug1: Host '[myservermgmt.northeurope.cloudapp.azure.com]:2200' is known and matches the ECDSA host key. 
debug1: Found key in /var/root/.ssh/known_hosts:2 
debug1: SSH2_MSG_NEWKEYS sent 
debug1: expecting SSH2_MSG_NEWKEYS 
debug1: SSH2_MSG_NEWKEYS received 
debug1: SSH2_MSG_SERVICE_REQUEST sent 
debug1: SSH2_MSG_SERVICE_ACCEPT received 
debug1: Authentications that can continue: publickey,password 
debug1: Next authentication method: publickey 
debug1: Offering RSA public key: /Users/me/.ssh/id_rsa 
debug1: Server accepts key: pkalg ssh-rsa blen 279 
debug1: Authentication succeeded (publickey). 
Authenticated to myservicemgmt.northeurope.cloudapp.azure.com ([52.178.215.121]:2200). 
debug1: Local connections to LOCALHOST:80 forwarded to remote address localhost:80 
debug1: Local forwarding listening on ::1 port 80. 
debug1: channel 0: new [port listener] 
debug1: Local forwarding listening on 127.0.0.1 port 80. 
debug1: channel 1: new [port listener] 
debug1: Requesting [email protected] 
debug1: forking to background 
debug1: Entering interactive session. 
debug1: client_input_global_request: rtype [email protected] want_reply 0 
debug1: Connection to port 80 forwarding to localhost port 80 requested. 
debug1: channel 2: new [direct-tcpip] 
channel 2: open failed: administratively prohibited: open failed 
debug1: channel 2: free: direct-tcpip: listening port 80 for localhost port 80, connect from 127.0.0.1 port 55718 to 127.0.0.1 port 80, nchannels 3 
debug1: Connection to port 80 forwarding to localhost port 80 requested. 

據我所知,這可能意味着PermitTunnel沒有在服務器上啓用。由於ssh隧道用於其他目的在我的機器上工作,我想知道ACS中是否有任何配置需要配置?我已經嘗試將ssh直接加入到DCOS主控中,但沒有成功。

任何幫助表示讚賞。

回答

0

AFAIK這可能意味着`PermitTunnel沒有在服務器上啓用。

不,這是AllowTcpForwarding在目標服務器的/etc/ssh/sshd_config。或PermitOpen指令。

另請注意,如果您未在根目錄下運行或具有特定權限,則無法綁定系統上的特權端口。

+0

我確實在DCOS主服務器上啓用了'AllowTcpForwarding'和'PermitTunnel'('myservermgmt.northeurope.cloudapp.azure.com'),但沒有任何改變。 'smitd_config'中沒有設置PermitOpen。 – Nils

+0

80是特權端口。你的本地操作系統是什麼? – Jakuje

+0

嘗試轉發到不同的本地端口時,轉發工作是否適合您? – Jakuje

相關問題