{"id":5099,"date":"2023-02-06T16:18:46","date_gmt":"2023-02-06T16:18:46","guid":{"rendered":"https:\/\/arzhost.com\/blogs\/?p=5099"},"modified":"2023-10-04T14:39:12","modified_gmt":"2023-10-04T14:39:12","slug":"fix-connection-reset-by-peer-error","status":"publish","type":"post","link":"https:\/\/arzhost.com\/blogs\/fix-connection-reset-by-peer-error\/","title":{"rendered":"How to Fix Connection Reset by Peer Error?"},"content":{"rendered":"<p>An SSH connection you were attempting to create or maintain has been blocked by a remote machine. It is not immediately clear from the &#8220;ssh exchange identification: read: How to Fix Connection Reset by Peer Error?&#8221; notification what caused the error.<\/p>\n<p>We must first determine the cause of the problem in order to effectively remedy it. The most practical solutions are offered in this article along with a detailed analysis of the most likely reasons.<\/p>\n<p>This guide will teach you how to resolve the &#8220;ssh exchange identification: Error message: Connection reset by peer.<\/p>\n<ul>\n<li>Necessary permissions to access a remote server<\/li>\n<li>A user account with root or sudo privileges<\/li>\n<\/ul>\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_74 counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #999;color:#999\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #999;color:#999\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/arzhost.com\/blogs\/fix-connection-reset-by-peer-error\/#What_Leads_to_the_SSH_Error_%E2%80%9CConnection_reset_by_peer%E2%80%9D\" >What Leads to the SSH Error &#8220;Connection reset by peer&#8221;?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/arzhost.com\/blogs\/fix-connection-reset-by-peer-error\/#Check_the_hosts_deny_and_hosts_allow_File\" >Check the hosts. deny and hosts. allow File<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/arzhost.com\/blogs\/fix-connection-reset-by-peer-error\/#How_to_Edit_hosts_deny_File\" >How to Edit hosts. deny File?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/arzhost.com\/blogs\/fix-connection-reset-by-peer-error\/#How_to_Edit_hosts_allow_File\" >How to Edit hosts. allow File?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/arzhost.com\/blogs\/fix-connection-reset-by-peer-error\/#Check_if_fail2ban_Banned_Your_IP_Address\" >Check if fail2ban Banned Your IP Address<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/arzhost.com\/blogs\/fix-connection-reset-by-peer-error\/#Examine_the_ssh_config_file\" >Examine the ssh config file.<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/arzhost.com\/blogs\/fix-connection-reset-by-peer-error\/#Conclusion\" >Conclusion<\/a><\/li><\/ul><\/nav><\/div>\n<h2><span class=\"ez-toc-section\" id=\"What_Leads_to_the_SSH_Error_%E2%80%9CConnection_reset_by_peer%E2%80%9D\"><\/span><strong>What Leads to the SSH Error &#8220;Connection reset by peer&#8221;?<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The <a href=\"https:\/\/en.wikipedia.org\/wiki\/Transmission_Control_Protocol\" target=\"_blank\" rel=\"noopener\">Transition Control Protocol (TCP) stream<\/a> was abruptly terminated by the remote machine, according to the &#8220;ssh exchange identification: read: Connection reset by peer&#8221; fault. Most of the time, a brief reboot of a remote server can resolve a fleeting outage or connectivity problem.<\/p>\n<p>You can avoid similar problems in your system in the future by understanding how to solve this one and identifying the root cause. The following are the most typical reasons for the error &#8220;ssh exchange identification: read: <span style=\"color: #000000;\"><strong>How to Fix Connection Reset by Peer Error?<\/strong><\/span>&#8220;:<\/p>\n<ol>\n<li>The Host-Based Access Control Lists are preventing the connection.<\/li>\n<li>By upgrading firewall rules, intrusion prevention software is blocking your IP (Fail2ban, Deny Hosts, etc.).<\/li>\n<li>changes to the configuration file for the SSH daemon.<\/li>\n<\/ol>\n<h2><span class=\"ez-toc-section\" id=\"Check_the_hosts_deny_and_hosts_allow_File\"><\/span><strong>Check the hosts. deny and hosts. allow File<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The hosts. deny and hosts. allow files to be TCP wrappers. As a security feature, these files are used to limit which IP address or hostname can establish a connection to the remote machine.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"How_to_Edit_hosts_deny_File\"><\/span><strong>How to Edit hosts. deny File?<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p><u>Access your remote server and open the hosts. deny the file using your preferred text editor. If you are using nano on a Debian-based system, enter the following command:<\/u><\/p>\n<ul>\n<li><code>sudo nano \/etc\/hosts.deny<\/code><\/li>\n<\/ul>\n<p>Comments are lines that are empty or that begin with the symbol &#8220;#.&#8221; See if the file contains your local IP or host name. If it&#8217;s there, get rid of it or comment it out because failing to do so prohibits you from creating a remote connection.<\/p>\n<p>Save the file after making the necessary adjustments, then close it. Try using SSH to reconnect.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"How_to_Edit_hosts_allow_File\"><\/span><strong>How to Edit hosts. allow File?<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Edit the hosts as an additional measure of safety.<\/p>\n<p><u>permit file rules for access on the hosts. allowing is used first. They are given precedence over host-specific rules. file denied Enter the next command to connect to the hosts. permit file:<\/u><\/p>\n<ul>\n<li><code>sudo nano \/etc\/hosts.allow<\/code><\/li>\n<\/ul>\n<p><u>Adding hostnames and IP addresses to the file creates exceptions to the hosts. deny settings. For instance, the etc\/hosts might have a stringent security policy. deny file, would prevent all hosts from accessing:<\/u><\/p>\n<ul>\n<li><code>STSH: ALL<\/code><\/li>\n<li><code>THEM ALL:<\/code><\/li>\n<\/ul>\n<p><u>You can then edit the etc\/hosts.allow file to add a single IP address, an IP range, or a hostname. Only the IP listed below would be permitted to make an SSH connection with your remote server by adding the following line:<\/u><\/p>\n<ul>\n<li><code>10.0.5, LOCAL, sshd<\/code><\/li>\n<\/ul>\n<p><em>How to Fix Connection Reset by Peer Error?<\/em> Remember that a security levels this restrictive can limit your ability to administer your distant servers.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Check_if_fail2ban_Banned_Your_IP_Address\"><\/span><strong>Check if fail2ban Banned Your IP Address<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>An intrusion protection system may have blocked your IP if you have repeatedly attempted to connect. In order to defend you from brute force attacks, a service called Fail2ban may mistakenly perceive your efforts at login as an attack.<\/p>\n<p><iframe title=\"YouTube video player\" src=\"https:\/\/www.youtube.com\/embed\/mITHJzcIuF4\" width=\"560\" height=\"315\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/p>\n<p>Fail2ban keeps track of and dynamically modifies firewall rules to <strong>block IP addresses<\/strong> that behave suspiciously. Like hosts, it keeps an eye on the logs. host and deny. Permit the files we&#8217;ve previously altered.<\/p>\n<p><u>We used the following command in our example to see if the iptables tool was denying your attempted connections:<\/u><\/p>\n<ul>\n<li><code>sudo iptables -L --line-number<\/code><\/li>\n<\/ul>\n<p>All authentication attempts will be listed in the output that appears in your terminal window. If you discover that a firewall is truly obstructing your SSH connection, you can use fail2ban to white-list your IP.<\/p>\n<p><u>Otherwise, the service will continuously block any additional attempts. Enter the following command to get to the fail2ban configuration file:<\/u><\/p>\n<ul>\n<li><code>Doing sudo nano \/etc\/fail2ban\/jail.conf<\/code><\/li>\n<\/ul>\n<p>The IP address or IP range you want to white-list can be added by uncommenting the line that reads &#8220;ignoreip =&#8221; in the file.<\/p>\n<p>Now, Fail2ban will make an exception and not flag the concerned IP for suspicious activity.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Examine_the_ssh_config_file\"><\/span><strong>Examine the ssh config file.<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Examine the authentication log entry if you are still getting the &#8220;ssh exchange identification: read: How to Fix Connection Reset by Peer Error?&#8221; problem. The SSH daemon transmits logging data to the system logs by default. After you&#8217;ve failed to log in, access the \/var\/log\/auth.log file. Type: to display the most recent log entries.<\/p>\n<ul>\n<li><code>\/var\/log\/auth.log, tail -f<\/code><\/li>\n<\/ul>\n<p>The output displays information about your user account, authentication key, and password, as well as the outcomes of your authentication attempts.<\/p>\n<p>You can use the information in the log to identify any problems in the sshd config configuration file. Any modifications to the file have the potential to change the conditions under which an ssh connection is initiated and cause the distant server to see the client as incompatible. the sshd config file can be accessed file type:<\/p>\n<ul>\n<li><code>sudo nano \/etc\/ssh\/sshd_config<\/code><\/li>\n<\/ul>\n<p>You can modify both fundamental parameters, such the default TCP port or SSH key pairs for authentication, as well as more complex features, like port-forwarding, using the sshd configuration file.<\/p>\n<p>For instance, the MaxStartups variable specifies the number of connections a system will allow in a given amount of time. It may be essential to adjust the default settings for this variable if your system establishes a lot of connections quickly. Otherwise, the remote machine might reject further ssh connection attempts.<\/p>\n<p><u>In order for changes to take effect after editing the sshd config file, you must restart the sshd service:<\/u><\/p>\n<ul>\n<li><code>sshd service restart<\/code><\/li>\n<\/ul>\n<p>Edit just the variables you are comfortable with. A bad configuration may cause a server to become unreachable.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Conclusion\"><\/span><strong>Conclusion<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>You have examined the most frequent causes of the &#8220;ssh exchange identification: Error message: &#8221; How to Fix Connection Reset by Peer Error?&#8221; You were able to find a solution by considering each possibility in turn, and you now know how to handle similar issues in the future.<\/p>\n<p>Numerous alternative causes exist, making it challenging to narrow down the problem. In the end, it might be necessary to get in touch with your <a href=\"https:\/\/arzhost.com\/\">host<\/a> if the error keeps happening.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>An SSH connection you were attempting to create or maintain has been blocked by a remote machine. It is not immediately clear from the &#8220;ssh exchange identification: read: How to Fix Connection Reset by Peer Error?&#8221; notification what caused the error. We must first determine the cause of the problem in order to effectively remedy [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":5100,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[98],"tags":[213,214,212],"table_tags":[],"class_list":["post-5099","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ssh","tag-connection-reset-by-peer","tag-fix","tag-guide"],"_links":{"self":[{"href":"https:\/\/arzhost.com\/blogs\/wp-json\/wp\/v2\/posts\/5099","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/arzhost.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/arzhost.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/arzhost.com\/blogs\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/arzhost.com\/blogs\/wp-json\/wp\/v2\/comments?post=5099"}],"version-history":[{"count":4,"href":"https:\/\/arzhost.com\/blogs\/wp-json\/wp\/v2\/posts\/5099\/revisions"}],"predecessor-version":[{"id":6012,"href":"https:\/\/arzhost.com\/blogs\/wp-json\/wp\/v2\/posts\/5099\/revisions\/6012"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/arzhost.com\/blogs\/wp-json\/wp\/v2\/media\/5100"}],"wp:attachment":[{"href":"https:\/\/arzhost.com\/blogs\/wp-json\/wp\/v2\/media?parent=5099"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/arzhost.com\/blogs\/wp-json\/wp\/v2\/categories?post=5099"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/arzhost.com\/blogs\/wp-json\/wp\/v2\/tags?post=5099"},{"taxonomy":"table_tags","embeddable":true,"href":"https:\/\/arzhost.com\/blogs\/wp-json\/wp\/v2\/table_tags?post=5099"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}