VanDyke Software Forums

Go Back   VanDyke Software Forums > General
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
Thread Tools Display Modes
  #1  
Old 11-15-2006, 07:59 PM
Casman Casman is offline
Registered User
 
Join Date: May 2005
Location: Melbourne Australia
Posts: 13
SecureCRT tabs question

Hi forum.

I have a question about opening tabs in SecureCRT.
Basically I open up a number of tabs to different servers and all works fine. Then I might open a new tab and the server might be VERY slow to connect (minutes sometimes). The problem I have is that I cannot access any of the other tabs until this new tab actually connects successfully or times out.

I can click all I want and all I get in the SecureCRT titlebar is SecureCRT not responding until the connection either is successful or fails, at which point I can get to the other tabs.

Any suggestions would be greatly appreciated.

Regards,
casman.
Reply With Quote
  #2  
Old 11-16-2006, 08:51 AM
miked's Avatar
miked miked is offline
Registered User
 
Join Date: Feb 2004
Posts: 2,040
That would be pretty annoying. So far I haven't been able to duplicate the problem but I've only been testing with the current official version, and I'm not certain that I'm following the same steps to reproduce.

Which version and build of SecureCRT are you using (Help / About SecureCRT)?

How are you opening the new tab (eg: Connect window, File menu / Connect in tab, command line SecureCRT /T /S SessionName, other)?
__________________
Mike
VanDyke Software
Technical Support
[http://www.vandyke.com/support]
Reply With Quote
  #3  
Old 11-16-2006, 07:55 PM
Casman Casman is offline
Registered User
 
Join Date: May 2005
Location: Melbourne Australia
Posts: 13
Hi miked.

I'm using the latest official version of SecureCRT.
Version details are:

Version 5.2.0 (build 229) - Official Release - October 10, 2006

I usually just press the 'connect' button, which gives me my 'connect' dialog. On the dialog, I have the 'Open in a tab' button ticked, and open my selection.

I usually have anywhere upto 8 tabs open at any one time, so when I get locked out of all my tabs until the connection either works or fails (which can take minutes sometimes) it gets very annoying.

Regards,
Casman.
Reply With Quote
  #4  
Old 11-17-2006, 10:30 PM
mekanik mekanik is offline
Registered User
 
Join Date: Jul 2005
Posts: 46
Hi Casman,

I have ran into the same situation on several occasions, however, it is so sporadic that I am unable to reproduce it consistently and it does not occur that often. One option that you may assist you is the following Global.ini option. miked, can you confirm that this solution is correct; not that it will work for Casman, but do not want to provide the wrong info either.

Code:
Default of b4 (hex value) = 180 (decimal value) in seconds
D:"Timeout"=000000b4

You can adjust this value to say the following for 30 seconds
D:"Timeout"=0000001e

Or the following for 1 minute (60 seconds)
D:"Timeout"=0000003c
However if you have a session that requires 3minutes to connect, I am not sure how much this will actually help. Is the latency issue to your server(s) due to accessing it via a low speed or intercontinental link or are you dealing with a reverse DNS issue?

Regards,
/mekanik/
Reply With Quote
  #5  
Old 11-17-2006, 10:52 PM
Casman Casman is offline
Registered User
 
Join Date: May 2005
Location: Melbourne Australia
Posts: 13
Hi Mekanik.

The problem I experience is consistent and happens all the time to me.
I use SecureCRT to connect to servers through firewalls and use NAT'ed IP addresses most of the time. Our link to some of our customers is very slow and it's these ones that give me the problem. As soon as I try to connect, SecureCRT locks up all my sessions until the connection succeeds or fails.

There are times when it get's so frustrating I actually revert to using Putty instead of SecureCRT to get my work done while SecureCRT sit's there connecting. This really frustrates me even more because I don't have the nice stuff like SecureFX integration which I use all the time.

Regards,
Casman.
Reply With Quote
  #6  
Old 11-20-2006, 10:51 AM
miked's Avatar
miked miked is offline
Registered User
 
Join Date: Feb 2004
Posts: 2,040
Casman,

I've created a bug report and let the product manager know. So far I've not been able to duplicate the problem, but it sounds like there's a slow network involved and I'm not sure how to duplicate that aspect. As I understand the steps to reproduce the problem you open multiple tabs to servers and all of these connections work fine. Then you open another tab and try to connect to a server that takes a long time to connect to. This causes the new tab to prevent other tabs from getting focus.

Is this accurate?

Would you be able to send trace options to support@vandyke.com in case the trace options reveal where/why the connection is preventing other tabs from getting focus?

To enable trace options, click on the "File" pull down menu and select "Trace Options". After trace options is enabled, try to connect to the server. After the problem occurs, right click inside the window and "Select All", then right click and select "Copy", then paste into an e-mail message.

You mentioned having to open PuTTY at times just so that you can get your work done. Is there a reason you choose to open PuTTY instead of opening a second SecureCRT window?

For example, does PuTTY not exhibit the same connection problem?

Would opening new connections to slow servers in a separate window be an acceptable workaround until this problem can be resolved?
__________________
Mike
VanDyke Software
Technical Support
[http://www.vandyke.com/support]
Reply With Quote
  #7  
Old 11-20-2006, 02:07 PM
Casman Casman is offline
Registered User
 
Join Date: May 2005
Location: Melbourne Australia
Posts: 13
Hi Miked.

Thanks for raising the bug report.

Your understanding of the error is correct. As for opening Putty, I was using it simply to not interfere with the session of SecureCRT trying to log on. I tried your suggestion of simply opening another SecureCRT window and using it and that seems to work OK. It allows me access to other servers while the other Window keeps trying to logon.

Thanks for the advice.

I have tried your trace option and here is the output once the tab responded back:

SecureCRT - Version 5.2.1 (build 256)
[LOCAL] : SSH2Core version 4.2.0.256
[LOCAL] : Connecting to 10.26.1.73:22 ...
[LOCAL] : Changing state from STATE_NOT_CONNECTED to STATE_EXPECT_KEX_INIT.
[LOCAL] : Using protocol SSH2
[LOCAL] : RECV : Remote Identifier = "SSH-1.99-OpenSSH_3.9"
[LOCAL] : CAP : Remote can re-key
[LOCAL] : CAP : Remote sends language in password change requests
[LOCAL] : CAP : Remote sends algorithm name in PK_OK packets
[LOCAL] : CAP : Remote sends algorithm name in public key packets
[LOCAL] : CAP : Remote sends algorithm name in signatures
[LOCAL] : CAP : Remote sends error text in open failure packets
[LOCAL] : CAP : Remote sends name in service accept packets
[LOCAL] : CAP : Remote includes port number in x11 open packets
[LOCAL] : CAP : Remote uses 160 bit keys for SHA1 MAC
[LOCAL] : CAP : Remote supports new diffie-hellman group exchange messages
[LOCAL] : CAP : Remote correctly handles unknown SFTP extensions
[LOCAL] : CAP : Remote correctly encodes OID for gssapi
[LOCAL] : CAP : Remote correctly uses connected addresses in forwarded-tcpip requests
[LOCAL] : CAP : Remote can do SFTP version 4
[LOCAL] : CAP : Remote x.509v3 uses ASN.1 encoding for DSA signatures
[LOCAL] : GSS : Requesting full delegation
[LOCAL] : GSS : [Kerberos] SPN : host@10.26.1.73
[LOCAL] : GSS : [Kerberos] Disabling gss mechanism
[LOCAL] : GSS : [Kerberos] InitializeSecurityContext() failed.
[LOCAL] : GSS : [Kerberos] The specified target is unknown or unreachable
[LOCAL] : The following key exchange method has been filtered from the key exchange method list because it is not supported: gss-group1-sha1-toWM5Slw5Ew8Mqkay+al2g==
[LOCAL] : GSS : Requesting full delegation
[LOCAL] : GSS : [Kerberos w/ Group Exchange] SPN : host@10.26.1.73
[LOCAL] : GSS : [Kerberos w/ Group Exchange] Disabling gss mechanism
[LOCAL] : GSS : [Kerberos w/ Group Exchange] InitializeSecurityContext() failed.
[LOCAL] : GSS : [Kerberos w/ Group Exchange] The specified target is unknown or unreachable
[LOCAL] : The following key exchange method has been filtered from the key exchange method list because it is not supported: gss-gex-sha1-toWM5Slw5Ew8Mqkay+al2g==
[LOCAL] : SEND : KEXINIT
[LOCAL] : RECV : Read kexinit
[LOCAL] : Available Remote Kex Methods = diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha1,diffie-hellman-group1-sha1
[LOCAL] : Selected Kex Method = diffie-hellman-group-exchange-sha1
[LOCAL] : Available Remote Host Key Algos = ssh-rsa,ssh-dss
[LOCAL] : Selected Host Key Algo = ssh-dss
[LOCAL] : Available Remote Send Ciphers = aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,arcfour,aes192-cbc,aes256-cbc,rijndael-cbc@lysator.liu.se,aes128-ctr,aes192-ctr,aes256-ctr
[LOCAL] : Selected Send Cipher = aes256-cbc
[LOCAL] : Available Remote Recv Ciphers = aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,arcfour,aes192-cbc,aes256-cbc,rijndael-cbc@lysator.liu.se,aes128-ctr,aes192-ctr,aes256-ctr
[LOCAL] : Selected Recv Cipher = aes256-cbc
[LOCAL] : Available Remote Send Macs = hmac-md5,hmac-sha1,hmac-ripemd160,hmac-ripemd160@openssh.com,hmac-sha1-96,hmac-md5-96
[LOCAL] : Selected Send Mac = hmac-sha1
[LOCAL] : Available Remote Recv Macs = hmac-md5,hmac-sha1,hmac-ripemd160,hmac-ripemd160@openssh.com,hmac-sha1-96,hmac-md5-96
[LOCAL] : Selected Recv Mac = hmac-sha1
[LOCAL] : Available Remote Compressors = none,zlib
[LOCAL] : Selected Compressor = zlib
[LOCAL] : Available Remote Decompressors = none,zlib
[LOCAL] : Selected Decompressor = zlib
[LOCAL] : Changing state from STATE_EXPECT_KEX_INIT to STATE_KEY_EXCHANGE.
[LOCAL] : SEND : KEXDH_GEX_REQUEST
[LOCAL] : RECV : KEXDH_GEX_GROUP
[LOCAL] : SEND : KEXDH_INIT
[LOCAL] : RECV : KEXDH_REPLY
[LOCAL] : SEND : NEWKEYS
[LOCAL] : Changing state from STATE_KEY_EXCHANGE to STATE_EXPECT_NEWKEYS.
[LOCAL] : RECV : NEWKEYS
[LOCAL] : Changing state from STATE_EXPECT_NEWKEYS to STATE_CONNECTION.
[LOCAL] : SEND: SERVICE_REQUEST[ssh-userauth]
[LOCAL] : RECV: SERVICE_ACCEPT[ssh-userauth] -- OK
[LOCAL] : SENT : USERAUTH_REQUEST [none]
[LOCAL] : RECV : USERAUTH_FAILURE, continuations [publickey,password,keyboard-interactive]
[LOCAL] : SENT : USERAUTH_REQUEST [password]
[LOCAL] : RECV : AUTH_SUCCESS
[LOCAL] : SEND: Pty Request (row: 42, col: 108)
[LOCAL] : RECV: pty request succeeded
[LOCAL] : SEND: agent forwarding request
[LOCAL] : RECV: agent request succeeded
[LOCAL] : SEND: shell request
[LOCAL] : RECV: shell request succeeded
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
* *
* THIS IS A PRIVATE SYSTEM OPERATED FOR HEWLETT PACKARD COMPANY BUSINESS. *
* AUTHORIZATION FROM HP MANAGEMENT IS REQUIRED TO USE THIS SYSTEM. USE *
* BY UNAUTHORIZED PERSONS IS PROHIBITED. *
* *
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
(c)Copyright 1983-2003 Hewlett-Packard Development Company, L.P.
(c)Copyright 1979, 1980, 1983, 1985-1993 The Regents of the Univ. of California
(c)Copyright 1980, 1984, 1986 Novell, Inc.
(c)Copyright 1986-2000 Sun Microsystems, Inc.
(c)Copyright 1985, 1986, 1988 Massachusetts Institute of Technology
(c)Copyright 1989-1993 The Open Software Foundation, Inc.
(c)Copyright 1990 Motorola, Inc.
(c)Copyright 1990, 1991, 1992 Cornell University
(c)Copyright 1989-1991 The University of Maryland
(c)Copyright 1988 Carnegie Mellon University
(c)Copyright 1991-2003 Mentat Inc.
(c)Copyright 1996 Morning Star Technologies, Inc.
(c)Copyright 1996 Progressive Systems, Inc.


RESTRICTED RIGHTS LEGEND
Use, duplication, or disclosure by the U.S. Government is subject to
restrictions as set forth in sub-paragraph (c)(1)(ii) of the Rights in
Technical Data and Computer Software clause in DFARS 252.227-7013.


Hewlett-Packard Company
3000 Hanover Street
Palo Alto, CA 94304 U.S.A.

Rights for non-DOD U.S. Government Departments and Agencies are as set
forth in FAR 52.227-19(c)(1,2).
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
* *
* THIS IS A PRIVATE SYSTEM OPERATED FOR HEWLETT PACKARD COMPANY BUSINESS. *
* AUTHORIZATION FROM HP MANAGEMENT IS REQUIRED TO USE THIS SYSTEM. USE *
* BY UNAUTHORIZED PERSONS IS PROHIBITED. *
* *
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
cbalakas@smohpv96cbalakas)> [LOCAL] : SEND: window-change (rows: 56, cols: 132)
Reply With Quote
  #8  
Old 11-20-2006, 03:42 PM
miked's Avatar
miked miked is offline
Registered User
 
Join Date: Feb 2004
Posts: 2,040
Casman,

If the bug report created for this problem leads to a new version of SecureCRT which we believe handles the slow connection better, we'll post here to let you know. For direct e-mail notification, please send e-mail to support@vandyke.com and refer to forum thread 1913.

I noticed that your trace options includes some Kerberos activity which is later discarded. Are you able to connect any faster to the server if you disable the Kerberos and Kerberos w/ Group Exchange Key exchange algorithms in Session Options / Connection / SSH2?
__________________
Mike
VanDyke Software
Technical Support
[http://www.vandyke.com/support]
Reply With Quote
  #9  
Old 11-21-2006, 01:41 PM
Casman Casman is offline
Registered User
 
Join Date: May 2005
Location: Melbourne Australia
Posts: 13
Hi Miked.

I disabled the Kerberos and Kerberos w/ Group Exchange Key exchange algorithms and it definitely logs on faster. Thanks for the info.

Just one other question with mekanik's suggestion re the timeout. Is there a global setting I can change somewhere? Just wondering because I'd like to change the setting in all my ini files but I have over 80 to change.

Regards,
Casman.
Reply With Quote
  #10  
Old 11-21-2006, 02:59 PM
miked's Avatar
miked miked is offline
Registered User
 
Join Date: Feb 2004
Posts: 2,040
Excellent - I'm glad to hear that disabling those options helped you logon faster.

The easiest way to make the change to all sessions is to edit the default session then apply the change to all sessions. Before making a change to all sessions by following the steps below, we strongly recommend making a backup of your configuration folder. Your configuration folder is specified in Global Options / General.
  • Click Edit Default Settings in Global Options / General / Default Session.
  • In Connection / SSH2, disable Kerberos and Kerberos w/ Group Exchange then click the OK button.
  • You'll be prompted with a window saying "Do you want to apply the changes that you made to the default session to ALL of your session? WARNING There is no UNDO for this change." If you select Yes, then all of your existing sessions will be modified.
New sessions will have the Kerberos and Kerberos w/ Group Exchange disabled as a result of modifying the default session.
__________________
Mike
VanDyke Software
Technical Support
[http://www.vandyke.com/support]
Reply With Quote
  #11  
Old 11-21-2006, 07:30 PM
mekanik mekanik is offline
Registered User
 
Join Date: Jul 2005
Posts: 46
Quote:
Originally Posted by Casman
Hi Miked.

Just one other question with mekanik's suggestion re the timeout. Is there a global setting I can change somewhere? Just wondering because I'd like to change the setting in all my ini files but I have over 80 to change.

Regards,
Casman.
miked,

I believe that Casman may be talking about the following post that I made earlier in this thread at Thread: 1913 / Post# 4. I could very well be wrong, but if this is the case, Casman you should be able to just modify the "Global.ini" file and it will apply to all sessions since this is a global configuration option. The only question is if the D:"Timeout"=000000b4" configuration option that I proposed relates to session timeout when connecting to a remote host that does not respond? miked, can you confirm this is correct?

/mekanik/
Reply With Quote
  #12  
Old 11-22-2006, 11:33 AM
miked's Avatar
miked miked is offline
Registered User
 
Join Date: Feb 2004
Posts: 2,040
Hi Mekanik,

I think D:"Timeout"=000000b4 is related to SecureFX, not SecureCRT, but I'll need to run some tests on a clean machine to be certain. In general, editing the Global.ini file is not the best practice. Some settings can only be modified by manually editing the INI file, but since the suggestion to disable Kerberos key exchange was helpful and the goal was to apply the change to all sessions, I wanted to make sure to mention the Edit Default Settings.
__________________
Mike
VanDyke Software
Technical Support
[http://www.vandyke.com/support]
Reply With Quote
  #13  
Old 12-05-2006, 01:26 PM
miked's Avatar
miked miked is offline
Registered User
 
Join Date: Feb 2004
Posts: 2,040
I found out more about the Global.ini Timeout setting and wanted to pass the information along. The timeout setting only has an impact on transfers and the Stop/Abort operation. It should the cause a stalled transfer to be interrupted (by SFX), which would then invoke the automatic/relentless retry mechanism. It is also used to limit the amount of time it takes the "Stop" operation to kill a directory listing in the session window. The timeout has no affect on other operations like logon. Is anybody wanting a connect timeout that you could set either in the GUI or in the INI files?
__________________
Mike
VanDyke Software
Technical Support
[http://www.vandyke.com/support]
Reply With Quote
  #14  
Old 01-26-2007, 11:12 AM
miked's Avatar
miked miked is offline
Registered User
 
Join Date: Feb 2004
Posts: 2,040
Casman,

We'd like to get more information to see if we can help with the lock-up problem.

Can you send us the global.ini and the session.ini for the session that causes the lock-up?

These are located in the configuration folder that's specified in Global Options / General.

Are you running any scripts in any tab or in the session?

Could you describe what you mean by SecureCRT locking up?

For example, Is SecureCRT completely unresponsive, or can you click on the menu?

What is the CPU usage when it locks up?

If there are other connections active, do they lock-up, too?
__________________
Mike
VanDyke Software
Technical Support
[http://www.vandyke.com/support]
Reply With Quote
  #15  
Old 01-30-2007, 10:48 PM
Casman Casman is offline
Registered User
 
Join Date: May 2005
Location: Melbourne Australia
Posts: 13
Hello Miked.

I am not running any scripts in the sessions.

CPU usage is normal during the lockup. I can access all other applications running at the time, only SecureCRT locks up. By locking up, I mean SecureCRT becomes unresponsive. All tabs are not accesible, and SecureCRT seems to simply hang. All I get is the title bar with 'SecureCRT not responding'.

I can open up other applications normally. It's just SecureCRT that hangs until it either crashes or comes back with a failed connection message. Once it comes back with a failed connection message, everything is back to normal and I can open tabs, access my existing open sessions and so on.

Also, how do I attach files to my response, so I can attach the global.ini and session.ini?

Regards,
Casman.
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 08:21 PM.


copyright 1995-2014 VanDyke Software, Inc.