4 Ways to Speed Up SSH Connections in Linux

[‘

n

SSH is the most popular and secure method for managing Linux servers remotely. One of the challenges with remote server management is connection speeds, especially when it comes to session creation between the remote and local machines.

n

There are several bottlenecks to this process, one scenario is when you are connecting to a remote server for the first time; it normally takes a few seconds to establish a session. However, when you try to start multiple connections in succession, this causes an overhead (combination of excess or indirect computation time, memory, bandwidth, or other related resources to carry out the operation).

n

In this article, we will share four useful tips on how to speed up remote SSH connections in Linux.

n

1. Force SSH Connection Over IPV4

n

OpenSSH supports both IPv4/IP6, but at times IPv6 connections tend to be slower. So you can consider forcing ssh connections over IPv4 only, using the syntax below:

n

# ssh -4 [emailxa0protected]rn

n

Alternatively, use the AddressFamily (specifies the address family to use when connecting) directive in your ssh configuration file /etc/ssh/ssh_config (global configuration) or ~/.ssh/config (user specific file).

n

The accepted values are “any”, “inet” for IPv4 only, or “inet6”.

n

$ vi ~.ssh/config rn

n

Disable SSH Connections on ipv6
Disable SSH Connections on ipv6

n

Here is a useful starter guide on configuring user specific ssh configuration file:

n

    n

  1. How to Configure Custom SSH Connections to Simplify Remote Access
  2. n

n

Additionally, on the remote machine, you can also instruct the sshd daemon to consider connections over IPv4 by using the above directive in the /etc/ssh/sshd_config file.

n

2. Disable DNS Lookup On Remote Machine

n

By default, sshd daemon looks up the remote host name, and also checks that the resolved host name for the remote IP address maps back to the very same IP address. This can result into delays in connection establishment or session creation.

n

The UseDNS directive controls the above functionality; to disable it, search and uncomment it in the /etc/ssh/sshd_config file. If it’s not set, add it with the value no.

n

UseDNS  norn

n

Disable SSH DNS Lookup
Disable SSH DNS Lookup

n

3. Reuse SSH Connection

n

An ssh client program is used to establish connections to an sshd daemon accepting remote connections. You can reuse an already-established connection when creating a new ssh session and this can significantly speed up subsequent sessions.

n

You can enable this in your ~/.ssh/config file.

n

Host *rntControlMaster autorntControlPath  ~/.ssh/sockets/%[emailxa0protected]%h-%prntControlPersist 600rn

n

The above configuration (Host *) will enable connection re-use for all remote servers you connect to using these directives:

n

    n

  • ControlMaster – enables the sharing of multiple sessions over a single network connection.
  • n

  • ControlPath – defines a path to the control socket used for connection sharing.
  • n

  • ControlPersist – if used together with ControlMaster, tells ssh to keep the master connection open in the background (waiting for future client connections) once the initial client connection has been closed.
  • n

n

Reuse SSH Connections
Reuse SSH Connections

n

You can enable this for connections to a specific remote server, for instance:

n

Host server1rntHostName   www.example.comrntIdentityFile  ~/.ssh/webserver.pemrn      tUser username_hererntControlMaster autorntControlPath  ~/.ssh/sockets/%[emailxa0protected]%h-%prntControlPersist  600rn

n

This way you only suffer the connection overhead for the first connection, and all subsequent connections will be much faster.

n

4. Use Specific SSH Authentication Method

n

Another way of speeding up ssh connections is to use a given authentication method for all ssh connections, and here we recommend configuring ssh passwordless login using ssh keygen in 5 easy steps.

n

Once that is done, use the PreferredAuthentications directive, within ssh_config files (global or user specific) above. This directive defines the order in which the client should try authentication methods (you can specify a command separated list to use more than one method).

n

PreferredAuthentications=publickey rn

n

SSH Authentication Method
SSH Authentication Method

n

Optionally, use this syntax below from the command line.

n

# ssh -o "PreferredAuthentications=publickey" [emailxa0protected]rn

n

If you prefer password authentication which is deemed unsecure, use this.

n

# ssh -o "PreferredAuthentications=password" [emailxa0protected]rn

n

Finally, you need to restart your sshd daemon after making all the above changes.

n

# systemctl restart sshdt#Systemdrn# service sshd restart tt#SysVInitrn

n

For more information about the directives used here, see the ssh_config and sshd_config man pages.

n

# man ssh_configrn# man sshd_config rn

n

Also check out these useful guides for securing ssh on Linux systems:

n

    n

  1. 5 Best Practices to Secure and Protect SSH Server
  2. n

  3. How to Disconnect Inactive or Idle SSH Connections in Linux
  4. n

n

That’s all for now! Do you have any tips/tricks for speeding up SSH connections. We would love to hear of other ways of doing this. Use the comment form below to share with us.

n

‘]