Forum Discussion

Chris_Olson_172's avatar
Chris_Olson_172
Icon for Nimbostratus rankNimbostratus
Aug 23, 2018

LTM SSH userauth_hostbased mismatch

We have thousands of entries in our log with the same message:

 

ltm 08-21 08:36:03 info LB01 sshd[1770]: userauth_hostbased mismatch: client sends servername.domain.com, but we resolve 10.28.66.48 to 10.28.66.48

 

SSH to this server/IP IS working so I don't understand the error message. The device in question is our Nagios server which interacts with the F5 on a regular basis. The server name resolves correctly so what is mismatched? Who is "we" in the log message? At a very minimum I need a way to STOP the logging of this message.

 

Product BIG-IP Version 11.5.4 Build 2.0.291 Edition Hotfix HF2

 

Any assistance is appreciated.

 

2 Replies

  • Here is a little more detail noting the logs prior to the mismatch error. This happens EVERY second.

     

    tm 08-23 15:42:02 info LB01 sshd[16559]: Accepted publickey for nagios from 10.28.66.48 port 45437 ssh2

     

    ltm 08-23 15:42:02 info LB01 sshd[16562]: Postponed publickey for nagios from 10.28.66.48 port 45437 ssh2

     

    ltm 08-23 15:42:02 info LB01 sshd[16559]: userauth_hostbased mismatch: client sends servername.domain t.com, but we resolve 10.28.66.48 to 10.28.66.48

     

  • Check your DNS PTR records, sounds like a reverse DNS query issue for servername.domain.com