IPv6 fails with "tcp-listener.c:284:" #525
Answered
by
yrutschle
onehalf3570
asked this question in
Q&A
Replies: 2 comments
|
The addresses in the protocol section need to resolve to
both, so typically you would have:
protocol: (
{ name: "ssh"; host: "localhost"; port: "9000"; }
);
and find in /etc/hosts:
127.0.0.1 localhost
::1 localhost
It's not possible to have translation with transparent
proxy, as by definition transparent proxying keeps the
external client address, and you can't transport an external
IPv6 address on an internal IPv4 address. You can however
use proxyprotocol to achieve a similar effect.
…On Sat, Feb 28, 2026 at 11:51:03AM -0800, onehalf3570 wrote:
Hi!
What's the way to specify IPv6 addresses correctly in the protocols section?
I've enabled IPv6 on the external interface (by adding another '{ host: }' to the 'listen' section), but the host addresses in the protocols section are still IPv4 only, so the connection fails with:
```
Feb 28 22:37:07 external_fqdn sslh-ev[60754]: accepting from 5
Feb 28 22:37:07 external_fqdn sslh-ev[60754]: writing deferred on fd -1
Feb 28 22:37:07 external_fqdn sslh-ev[60889]: connect: No child processes
Feb 28 22:37:07 external_fqdn sslh-ev[60754]: hexdump of incoming packet:
Feb 28 22:37:07 external_fqdn sslh-ev[60754]: 0x000000: 53 53 48 2d 32 2e 30 2d 4f 70 65 6e 53 53 48 5f SSH-2.0-OpenSSH_
Feb 28 22:37:07 external_fqdn sslh-ev[60754]: 0x000010: 31 30 2e 30 70 32 20 44 65 62 69 61 6e 2d 37 20 10.0p2 Debian-7
Feb 28 22:37:07 external_fqdn sslh-ev[60754]: probing for tls
Feb 28 22:37:07 external_fqdn sslh-ev[60754]: Request did not begin with TLS handshake.
Feb 28 22:37:07 external_fqdn sslh-ev[60754]: probed for tls: PROBE_NEXT
Feb 28 22:37:07 external_fqdn sslh-ev[60754]: probing for tls
Feb 28 22:37:07 external_fqdn sslh-ev[60754]: Request did not begin with TLS handshake.
Feb 28 22:37:07 external_fqdn sslh-ev[60754]: probed for tls: PROBE_NEXT
Feb 28 22:37:07 external_fqdn sslh-ev[60754]: probing for tls
Feb 28 22:37:07 external_fqdn sslh-ev[60754]: Request did not begin with TLS handshake.
Feb 28 22:37:07 external_fqdn sslh-ev[60754]: probed for tls: PROBE_NEXT
Feb 28 22:37:07 external_fqdn sslh-ev[60754]: probing for regex
Feb 28 22:37:07 external_fqdn sslh-ev[60754]: probed for regex: PROBE_MATCH
Feb 28 22:37:07 external_fqdn sslh-ev[60754]: closing fd 10
Feb 28 22:37:07 external_fqdn sslh-ev[60889]: closing fd 8
Feb 28 22:37:07 external_fqdn sslh-ev[60889]: closing fd 9
Feb 28 22:37:07 external_fqdn sslh-ev[60889]: Proto timeout -1: 0/0 cnx
Feb 28 22:37:07 external_fqdn sslh-ev[60889]: Endpoint 5 -1: 1/0 cnx
Feb 28 22:37:07 external_fqdn sslh-ev[60889]: tcp-listener.c:284:
Feb 28 22:37:07 external_fqdn sslh-ev[60754]: Proto regex -1: 0/0 cnx
Feb 28 22:37:07 external_fqdn sslh-ev[60754]: Endpoint 5 -1: 1/0 cnx
```
(IPv4 connections are ok)
As I understand there would be no IPv4 <-> IPv6 translation (or at least not in transparent proxy mode? Didn't check the code yet), but what's the way to have a dual stack configuration then?
Thanks.
--
Reply to this email directly or view it on GitHub:
#525
You are receiving this because you are subscribed to this thread.
Message ID: ***@***.***>
|
0 replies
Answer selected by
onehalf3570
|
Thank you! It works. Indeed, I missed the fact that transparent proxying won't work across different protocols ;) For the sake of completeness, here is the interfaces file used (also turned out to be not very obvious for the dual stack + dummy combination): |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Hi!
What's the way to specify IPv6 addresses correctly in the protocols section?
I've enabled IPv6 on the external interface (by adding another '{ host: }' to the 'listen' section), but the host addresses in the protocols section are still IPv4 only, so the connection fails with:
(IPv4 connections are ok)
As I understand there would be no IPv4 <-> IPv6 translation (or at least not in transparent proxy mode? Didn't check the code yet UPD: yes:
sslh/common.c
Line 425 in e2d01a7
UPD: I guess the proper way would be to allow multiple 'host:' entries in the protocols section, at the moment such approach fails with:
..56 being the line with the extra (IPv6) address for that matcher
Thanks.
All reactions