I have sshd log entries from the past seemingly randomly mixed in (in time) with the presently occurring log entries.
No remote hosts log to this server, rsyslog serves only this box. External access to rsyslog listener is blocked at firewall. Sshd version: OpenSSH_6.6.1p1 Ubuntu-2ubuntu2. Sshd was logging at daemon:info, but I've since raised to daemon:verbose. TcpKeepAlive is yes on server. The entries seem to appear as valid client disconnect messages. The client IP is known to me, and he is permitted to ssh by firewall rules. Client version: OpenSSH_6.6.1p1 Ubuntu-2ubuntu2. The client's /etc/ssh/ssh_config specifies ServerAliveInterval 60. The client is creating port redirects on the server. Then a process on server periodically pipes data to the client port using netcat.
The erroneous datetime stamp, as well as seemingly old log entries being mixed in with current log entries are the concerns. Could this a symptom of old broken sessions leftover from unclean exit?
Any suggestions are welcome, thanks.