Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

the GFW can block SSH connection based on data flow rate? #169

Closed
braindevices opened this issue Feb 2, 2018 · 6 comments
Closed

the GFW can block SSH connection based on data flow rate? #169

braindevices opened this issue Feb 2, 2018 · 6 comments
Labels

Comments

@braindevices
Copy link

I just found out the GFW will block IP for 1 hour, if download large file through ssh. This is crazy. So now I cannot obtain business data through ssh... Any data flow below 50KB/s is OK ...
Test inside China Telecomm, no such feature in China unicom.
Any one know any solution for this?

@SerCom-KC SerCom-KC added the Meta label Feb 2, 2018
@SerCom-KC
Copy link
Contributor

Kind of off-topic, but I prefer not closing this immediately.

And, IMO, no "actual" solution for this.
You'll probably have to make SSH traffic through VPN or something or just leave "中国奠信" alone

@DDoSolitary DDoSolitary added Question and removed Meta labels Feb 4, 2018
@DDoSolitary
Copy link

Maybe a "question" label is better.

@beyondgfw
Copy link
Member

beyondgfw commented Feb 4, 2018

It's been obersved for a long time that GFW does detect and block SSH connections.

You can try using some encrypted proxying techniques in front of your SSH server (e.g. VPN as @SerCom-KC mentions).

Or if you can control your SSH server, there is a fork of OpenSSH server with an obfuscated protocol, and putty has built-in clilent support for it. Try changing your server port to some value other than 22 and use the obfuscated server, though it is not guaranteed to work...

@SerCom-KC
Copy link
Contributor

SerCom-KC commented Feb 4, 2018

Maybe a "question" label is better.

I thought that was for hosts-related questions only lol

@braindevices
Copy link
Author

@SerCom-KC thanks a lot for keeping this topic open. @beyondgfw I am going to try the obfuscated protocol, let's see what will happen.

@SerCom-KC
Copy link
Contributor

Close for now. Let me know if you have any reasons to keep this open

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Development

No branches or pull requests

3 participants