# SSH via IngressRouteTCP?

**URL:** <https://community.traefik.io/t/ssh-via-ingressroutetcp/13577>\
**Category:** Traefik v2\
**Tags:** kubernetes-crd\
**Created:** [February 23, 2022, 9:36pm UTC](https://community.traefik.io/t/ssh-via-ingressroutetcp/13577 "2022-02-23T21:36:24Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![kallisti5](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/kallisti5/32/1216_2.png) [@kallisti5](https://community.traefik.io/u/kallisti5)\
**Post date:** [February 23, 2022, 9:36pm UTC](https://community.traefik.io/t/ssh-via-ingressroutetcp/13577/1 "2022-02-23T21:36:25Z")

</div>

Anyone have any experience doing SSH over IngressRouteTCP?  
Overall it should be working, but Traefik is doing something weird to the traffic.

```auto
$ ssh XX.XX.XX.XX -v
OpenSSH_8.8p1, OpenSSL 1.1.1m 14 Dec 2021
debug1: Reading configuration data /home/kallisti5/.ssh/config
debug1: /home/kallisti5/.ssh/config line 6: Applying options for XX.XX.XX.XX
debug1: Reading configuration data /etc/ssh/ssh_config
debug1: Connecting to XX.XX.XX.XX [XX.XX.XX.XX] port 22.
debug1: Connection established.
debug1: identity file /home/kallisti5/.ssh/id_ed25519 type 3
debug1: identity file /home/kallisti5/.ssh/id_ed25519-cert type -1
debug1: Local version string SSH-2.0-OpenSSH_8.8
debug1: Remote protocol version 2.0, remote software version GerritCodeReview_3.3.8 (APACHE-SSHD-2.4.0)
debug1: compat_banner: no match: GerritCodeReview_3.3.8 (APACHE-SSHD-2.4.0)
debug1: Authenticating to XX.XX.XX.XX:22 as 'kallisti5'
debug1: load_hostkeys: fopen /home/kallisti5/.ssh/known_hosts2: No such file or directory
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts: No such file or directory
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts2: No such file or directory
debug1: SSH2_MSG_KEXINIT sent
Bad packet length 1433301877.
ssh_dispatch_run_fatal: Connection to XX.XX.XX.XX port 22: message authentication code incorrect

```

Here's the IngressRouteTCP:

```auto
---
apiVersion: traefik.containo.us/v1alpha1
kind: IngressRouteTCP
metadata:
  name: git-ingresstcp
spec:
  entryPoints:
    - gitssh
  routes:
  - match: "HostSNI(`*`)"
    services:
    - name: git-ssh
      port: git
      weight: 10
      terminationDelay: 90000
      proxyProtocol:
        version: 1

```

I can access the SSH port from the service just fine via kubectl port-forward. I can also access the SSH port just fine from within the Traefik container using the internal IP address Traefik is using for the service per the WebUI.

Traefik has a dedicated entry point for this:

```auto
        - --entrypoints.gitssh.address=:22

```

---

<div class="post-metadata">

**Author:** ![Th3ABombs](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/th3abombs/32/5271_2.png) [@Th3ABombs](https://community.traefik.io/u/Th3ABombs)\
**Post date:** [April 27, 2022, 2:16pm UTC](https://community.traefik.io/t/ssh-via-ingressroutetcp/13577/2 "2022-04-27T14:16:10Z")

</div>

Hi  
unfortunately, same problem for me

```auto
debug3: send packet: type 20
debug1: SSH2_MSG_KEXINIT sent
Bad packet length 1231976033.
debug3: send packet: type 1
ssh_dispatch_run_fatal: Connection to xx.xx.xx.xx port 22: message authentication code incorrect

```

deleting and reapplying the ingressroutetcp sometimes works...
