<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site to Site VPN no SSH access to servers in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-no-SSH-access-to-servers/m-p/107738#M14441</link>
    <description>&lt;P&gt;If&amp;nbsp;&lt;SPAN&gt;SSH is in Excluded Services ... then it will be excluded from the VPN and be sent in the clear. That's what that setting tells the firewall to do. If the destination is private, you won't be able to reach it over the Internet without using the VPN.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Why is SSH in the Excluded Services for the VPN? There may be a better way to meet the requirement.&lt;/P&gt;</description>
    <pubDate>Wed, 13 Jan 2021 15:55:55 GMT</pubDate>
    <dc:creator>Bob_Zimmerman</dc:creator>
    <dc:date>2021-01-13T15:55:55Z</dc:date>
    <item>
      <title>Site to Site VPN no SSH access to servers</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-no-SSH-access-to-servers/m-p/107724#M14437</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm new to checkpoint and currently I'm confused with one case.&lt;/P&gt;&lt;P&gt;While I'm connected to the Site A network behind Site A Gateway which is connected via Site-to-Site VPN to B Gateway I'm unable to access resources located in B network via SSH.&lt;/P&gt;&lt;P&gt;But resources is still reachable via https, http, icmp.&lt;BR /&gt;Also we have IPsec VPN configuration with Network C, and for remote VPN clients everything is working.&lt;/P&gt;&lt;P&gt;What I can see in logs that source: My PC, dst: Linux server, action: accept, origin: VPN Gateway, so from here everything looks just fine but in same time Linux server not receiving any connections to it.&lt;/P&gt;&lt;P&gt;In same time connection via RDP to Windows servers are working.&lt;/P&gt;&lt;P&gt;VPN Community topology is Star, and SSH is in Excluded Services.&lt;/P&gt;&lt;P&gt;Telnet from PC showing that port 22 is closed.&lt;/P&gt;&lt;P&gt;GW versions R80.30&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;If any other info is needed please let me know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Br, Arthurs&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 14:54:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-no-SSH-access-to-servers/m-p/107724#M14437</guid>
      <dc:creator>Arthurs</dc:creator>
      <dc:date>2021-01-13T14:54:22Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN no SSH access to servers</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-no-SSH-access-to-servers/m-p/107726#M14439</link>
      <description>&lt;P&gt;I've checked security policy rules and all traffic and services are allowed from Network A to Network B, also I've tried to create rule for testing purposes allowing SSH service from my PC to Linux server, and again in logs I could see that these connection is accepted and correct policy number.&lt;/P&gt;&lt;P&gt;Regarding server firewall is disabled and it's listening for port 22 from all networks.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 15:01:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-no-SSH-access-to-servers/m-p/107726#M14439</guid>
      <dc:creator>Arthurs</dc:creator>
      <dc:date>2021-01-13T15:01:38Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN no SSH access to servers</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-no-SSH-access-to-servers/m-p/107737#M14440</link>
      <description>&lt;P&gt;If SSH is listed in Excluded Services and it’s not working, maybe you need to remove it from Excluded Services?&lt;BR /&gt;Or the remote site needs to update their configuration so it’s added as an Excluded Service?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 15:50:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-no-SSH-access-to-servers/m-p/107737#M14440</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-13T15:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN no SSH access to servers</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-no-SSH-access-to-servers/m-p/107738#M14441</link>
      <description>&lt;P&gt;If&amp;nbsp;&lt;SPAN&gt;SSH is in Excluded Services ... then it will be excluded from the VPN and be sent in the clear. That's what that setting tells the firewall to do. If the destination is private, you won't be able to reach it over the Internet without using the VPN.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Why is SSH in the Excluded Services for the VPN? There may be a better way to meet the requirement.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 15:55:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-no-SSH-access-to-servers/m-p/107738#M14441</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2021-01-13T15:55:55Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN no SSH access to servers</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-no-SSH-access-to-servers/m-p/107787#M14457</link>
      <description>&lt;P&gt;I will try to remove it from Excluded later today and see if it will work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What do you mean by "&lt;SPAN&gt;Or the remote site needs to update their configuration so it’s added as an Excluded Service?" The "Remote site", lets call it network B and my site Network A are connected to each other via IPsec Tunnel and using one VPN community where this setting are set, is there any other place where this configuration should be set for Network B? Both Firewalls in these networks are centrally managed.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 06:27:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-no-SSH-access-to-servers/m-p/107787#M14457</guid>
      <dc:creator>Arthurs</dc:creator>
      <dc:date>2021-01-14T06:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN no SSH access to servers</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-no-SSH-access-to-servers/m-p/107788#M14458</link>
      <description>&lt;P&gt;I will try to remove it from Excluded Services later today and update here about results.&lt;/P&gt;&lt;P&gt;What do you mean by "&lt;SPAN&gt;Or the remote site needs to update their configuration so it’s added as an Excluded Service?&lt;/SPAN&gt;"&lt;/P&gt;&lt;P&gt;Remote site is Network B, my site is Network A, they are both connected via IPsec tunnel which is a part of VPN community where this setting are set, is there any other place where I should change this configuration for Network B?&lt;/P&gt;&lt;P&gt;Both Firewalls are centrally managed.&amp;nbsp;&lt;BR /&gt;I'm connecting to server private IP address, not to public gateway IP.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 06:32:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-no-SSH-access-to-servers/m-p/107788#M14458</guid>
      <dc:creator>Arthurs</dc:creator>
      <dc:date>2021-01-14T06:32:41Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN no SSH access to servers</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-no-SSH-access-to-servers/m-p/107797#M14460</link>
      <description>&lt;P&gt;Thanks, I have removed SSH from Excluded Services and now connection is working.&lt;/P&gt;&lt;P&gt;I'm still not sure about what did you mean "remote site needs update their configuration" the remote site and my location are both connected via IPsec tunnel and are part of same VPN community, so they share Excluded Services list, or I understand this wrong?P.S. I have replied 2 times these morning, but replies didn't appear, I'm not sure is it some kind pre-post checks happening, but in case there will be 3 replies sorry for that.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 07:55:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-no-SSH-access-to-servers/m-p/107797#M14460</guid>
      <dc:creator>Arthurs</dc:creator>
      <dc:date>2021-01-14T07:55:44Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN no SSH access to servers</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-no-SSH-access-to-servers/m-p/107865#M14481</link>
      <description>&lt;P&gt;There are a lot of ways to use Check Point VPN-1 and a lot of ways to use SSH. Depending on what you want to do with either, you may need to exclude SSH, or define things more granularly with user.def.&lt;/P&gt;
&lt;P&gt;For example, if you control both sites, you may want to exclude SSH so you can still SSH from one site to the firewall at the other site for troubleshooting even if the VPN is broken.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 21:14:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-no-SSH-access-to-servers/m-p/107865#M14481</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2021-01-14T21:14:13Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN no SSH access to servers</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-no-SSH-access-to-servers/m-p/107885#M14483</link>
      <description>&lt;P&gt;“&lt;SPAN&gt;Or the remote site needs to update their configuration so it’s added as an Excluded Service” assumed the site was managed/controlled by a third party.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2021 04:45:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-no-SSH-access-to-servers/m-p/107885#M14483</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-15T04:45:30Z</dc:date>
    </item>
  </channel>
</rss>

