<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SCP disable - SSH open in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SCP-disable-SSH-open/m-p/275698#M105007</link>
    <description>&lt;P&gt;Hi Folks,&lt;/P&gt;&lt;P&gt;I have an Open Server running Gaia R82 and some gateways. Our Security requested some hardening on the server. One question is: Can I disable scp on the server while leaving ssh open?&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
    <pubDate>Fri, 17 Apr 2026 14:25:21 GMT</pubDate>
    <dc:creator>iannis12</dc:creator>
    <dc:date>2026-04-17T14:25:21Z</dc:date>
    <item>
      <title>SCP disable - SSH open</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SCP-disable-SSH-open/m-p/275698#M105007</link>
      <description>&lt;P&gt;Hi Folks,&lt;/P&gt;&lt;P&gt;I have an Open Server running Gaia R82 and some gateways. Our Security requested some hardening on the server. One question is: Can I disable scp on the server while leaving ssh open?&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2026 14:25:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SCP-disable-SSH-open/m-p/275698#M105007</guid>
      <dc:creator>iannis12</dc:creator>
      <dc:date>2026-04-17T14:25:21Z</dc:date>
    </item>
    <item>
      <title>Re: SCP disable - SSH open</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SCP-disable-SSH-open/m-p/275699#M105008</link>
      <description>&lt;P&gt;If your Gaia login shell is &lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_Gaia_AdminGuide/Content/Topics-GAG/Introduction-to-CLI.htm?tocpath=Introduction%20to%20the%20Command%20Line%20Interface%7C_____0" target="_self"&gt;Clish&lt;/A&gt; (Default), then SCP is only possible for dedicated&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Creating-an-scpuser-account-on-Gaia-Clish/m-p/5819/highlight/true#M211" target="_self"&gt;scponly&lt;/A&gt; Accounts, which need to be manually created. So yes, you can disable SCP by leaving SSH open. You just need to verify that no login account has /bin/bash or /usr/bin/scponly configured as login shell. Btw, experienced linux users can transfer files via pure SSH. You can never avoid file transfers if you allow SSH.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2026 14:41:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SCP-disable-SSH-open/m-p/275699#M105008</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2026-04-17T14:41:01Z</dc:date>
    </item>
  </channel>
</rss>

