<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: File Transfers over port 22 are failing in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-Transfers-over-port-22-are-failing/m-p/153677#M25814</link>
    <description>&lt;P&gt;The Confidence rating of that "&lt;SPAN&gt;Malicious Payload Encoding Remote Code Execution"&amp;nbsp;&lt;/SPAN&gt;protection is Medium, if it were Low I'd be more willing to accept it going off randomly like that.&amp;nbsp; My guess is that this signature is looking for a very short sequence of bytes (&amp;lt;5) without any further context information, and every now and then an encrypted stream happens to match it and get blocked.&amp;nbsp; Seems unlikely but certainly not impossible.&amp;nbsp; Would need to see packet captures of a few separate instances to try to determine what it is seeing that is causing the false positive.&lt;/P&gt;
&lt;P&gt;This vulnerability does not appear to have a CVE number and is something Check Point came up with on their own (CPAI-2013-3606) so only R&amp;amp;D will be able to provide further details.&amp;nbsp; Based on how it is behaving and that multiple posters have seen this behavior, I'd argue that the Confidence level of this protection should be changed to Low.&amp;nbsp; Who knows if this attack method is even relevant anymore; this is an advisory from almost 10 years ago.&lt;/P&gt;</description>
    <pubDate>Sat, 23 Jul 2022 21:07:36 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2022-07-23T21:07:36Z</dc:date>
    <item>
      <title>File Transfers over port 22 are failing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-Transfers-over-port-22-are-failing/m-p/153030#M25635</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We have a number of automated file transfers to different vendors that are failing.&amp;nbsp; The large files have to be retried and the large number of files(100+) have to be restarted.&amp;nbsp; Files are transferred via port 22.&amp;nbsp; Someone has to babysit these file transfer jobs to ensure they get completed.&amp;nbsp; This is happening on both inbound and outbound file transfers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is affecting every vendor we send files to and any host we send or receive from so this is looking like it's the firewall that might be the bottleneck.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&amp;nbsp; What can I check on the gateway or settings I can change to fix this?&lt;/P&gt;&lt;P&gt;I am running R80.30.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2022 18:48:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-Transfers-over-port-22-are-failing/m-p/153030#M25635</guid>
      <dc:creator>David_Chau</dc:creator>
      <dc:date>2022-07-14T18:48:14Z</dc:date>
    </item>
    <item>
      <title>Re: File Transfers over port 22 are failing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-Transfers-over-port-22-are-failing/m-p/153031#M25636</link>
      <description>&lt;P&gt;First thing I would check is logs in dashboard on port 22 and see why it might be failing. So say if remote iP is 1.2.3.4, you can do filter like this -&amp;gt; dst:1.2.3.4 OR port:22 OR action:Drop&lt;/P&gt;
&lt;P&gt;You can also use AND instead of OR. From ssh, just run something like this -&amp;gt; fw ctl zdebug + drop | grep 1.2.3.4 | grep 22&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2022 19:50:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-Transfers-over-port-22-are-failing/m-p/153031#M25636</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-07-14T19:50:30Z</dc:date>
    </item>
    <item>
      <title>Re: File Transfers over port 22 are failing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-Transfers-over-port-22-are-failing/m-p/153032#M25637</link>
      <description>&lt;P&gt;Hi Andy,&lt;/P&gt;&lt;P&gt;There are no drops in traffic since we have a specific rule to allow this.&amp;nbsp; Resource utilization on the gateways are also low.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2022 19:59:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-Transfers-over-port-22-are-failing/m-p/153032#M25637</guid>
      <dc:creator>David_Chau</dc:creator>
      <dc:date>2022-07-14T19:59:40Z</dc:date>
    </item>
    <item>
      <title>Re: File Transfers over port 22 are failing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-Transfers-over-port-22-are-failing/m-p/153033#M25638</link>
      <description>&lt;P&gt;Ok, fair enough...do we see anything in the logs at all or it shows traffic being accepted?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2022 20:05:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-Transfers-over-port-22-are-failing/m-p/153033#M25638</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-07-14T20:05:39Z</dc:date>
    </item>
    <item>
      <title>Re: File Transfers over port 22 are failing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-Transfers-over-port-22-are-failing/m-p/153034#M25639</link>
      <description>&lt;P&gt;Logs show accepted.&amp;nbsp; I am thinking about enabling log accounting to gather more details on this traffic.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2022 20:10:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-Transfers-over-port-22-are-failing/m-p/153034#M25639</guid>
      <dc:creator>David_Chau</dc:creator>
      <dc:date>2022-07-14T20:10:46Z</dc:date>
    </item>
    <item>
      <title>Re: File Transfers over port 22 are failing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-Transfers-over-port-22-are-failing/m-p/153035#M25640</link>
      <description>&lt;P&gt;That, but you can also try do fw monitor filters, both below (assuming IP is 1.2.3.4)&lt;/P&gt;
&lt;P&gt;fw monitor -e "accept host(1.2.3.4) and port(22);"&lt;/P&gt;
&lt;P&gt;fw monitor -F '0,1.2.3.4,0,22,0'&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-F flag lets you do in order 'src IP, dst IP, src port, dst port, protocol'&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2022 20:13:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-Transfers-over-port-22-are-failing/m-p/153035#M25640</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-07-14T20:13:47Z</dc:date>
    </item>
    <item>
      <title>Re: File Transfers over port 22 are failing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-Transfers-over-port-22-are-failing/m-p/153062#M25650</link>
      <description>&lt;P&gt;morning,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;anything in SSH logs, that shows why session was dropping ?&lt;/P&gt;
&lt;P&gt;could it be that it was taking too much and for a while nothing happened so it was closed ?&lt;/P&gt;
&lt;P&gt;you could also try and look to enable some keepalive probing&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you,&lt;/P&gt;
&lt;P&gt;PS: look on port 22 what timeout it has set - mine is 3600 - so the ssh connection would be kept for up to 1 hour before it would be dropped from the CKP FWL if not traffic happens&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2022 05:12:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-Transfers-over-port-22-are-failing/m-p/153062#M25650</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2022-07-15T05:12:35Z</dc:date>
    </item>
    <item>
      <title>Re: File Transfers over port 22 are failing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-Transfers-over-port-22-are-failing/m-p/153086#M25657</link>
      <description>&lt;P&gt;Enable Accounting on the rule(s) matching the transfers and also try enabling TCP state logging to get more information about what is going on when the connections terminate:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk101221&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;sk101221: TCP state logging&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2022 11:28:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-Transfers-over-port-22-are-failing/m-p/153086#M25657</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-07-15T11:28:00Z</dc:date>
    </item>
    <item>
      <title>Re: File Transfers over port 22 are failing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-Transfers-over-port-22-are-failing/m-p/153123#M25677</link>
      <description>&lt;P&gt;Try using plain tcp/22 without protocol selected. We had nasty connection drops, but with other ports though.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2022 19:09:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-Transfers-over-port-22-are-failing/m-p/153123#M25677</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2022-07-15T19:09:29Z</dc:date>
    </item>
    <item>
      <title>Re: File Transfers over port 22 are failing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-Transfers-over-port-22-are-failing/m-p/153572#M25773</link>
      <description>&lt;P&gt;Found the issue.&amp;nbsp; It was the IPS Protection, "Malicious Payload Encoding Remote Code Execution", that are intermittently blocking these transfers.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://threatpoint.checkpoint.com/ThreatPortal/threat?threatType=protection&amp;amp;threatId=PAYLOAD_ENCODER" target="_blank"&gt;https://threatpoint.checkpoint.com/ThreatPortal/threat?threatType=protection&amp;amp;threatId=PAYLOAD_ENCODER&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Any reason why this IPS protection signature would block the file then allow the file to transfer when reattempted?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jul 2022 19:27:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-Transfers-over-port-22-are-failing/m-p/153572#M25773</guid>
      <dc:creator>David_Chau</dc:creator>
      <dc:date>2022-07-21T19:27:57Z</dc:date>
    </item>
    <item>
      <title>Re: File Transfers over port 22 are failing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-Transfers-over-port-22-are-failing/m-p/153573#M25774</link>
      <description>&lt;P&gt;That's weird, as it should be quite visible in the FWL logs while looking for SSH traffic from A to B.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Good that you found what was impacting your traffic that randomly.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jul 2022 20:01:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-Transfers-over-port-22-are-failing/m-p/153573#M25774</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2022-07-21T20:01:25Z</dc:date>
    </item>
    <item>
      <title>Re: File Transfers over port 22 are failing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-Transfers-over-port-22-are-failing/m-p/153575#M25775</link>
      <description>&lt;P&gt;Can you see any logs on that IPS protection?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jul 2022 20:09:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-Transfers-over-port-22-are-failing/m-p/153575#M25775</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-07-21T20:09:10Z</dc:date>
    </item>
    <item>
      <title>Re: File Transfers over port 22 are failing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-Transfers-over-port-22-are-failing/m-p/153576#M25776</link>
      <description>&lt;P&gt;Yes, I see the block in the logs and then the traffic is allowed after the file transfer is restarted.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jul 2022 20:11:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-Transfers-over-port-22-are-failing/m-p/153576#M25776</guid>
      <dc:creator>David_Chau</dc:creator>
      <dc:date>2022-07-21T20:11:34Z</dc:date>
    </item>
    <item>
      <title>Re: File Transfers over port 22 are failing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-Transfers-over-port-22-are-failing/m-p/153577#M25777</link>
      <description>&lt;P&gt;If I were you, I would add an exception for that, to be on the safe side.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jul 2022 20:13:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-Transfers-over-port-22-are-failing/m-p/153577#M25777</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-07-21T20:13:19Z</dc:date>
    </item>
    <item>
      <title>Re: File Transfers over port 22 are failing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-Transfers-over-port-22-are-failing/m-p/153579#M25778</link>
      <description>&lt;P&gt;Just added the exception.&amp;nbsp; The business is not very happy this was the issue.&amp;nbsp; Curious why this block was so intermittent.&amp;nbsp; These are daily transfers containing the same type of data.&amp;nbsp; These transfers are also encrypted so not sure how this signature flagged this as malicious payload, maybe because of the high volume?&amp;nbsp; Anybody from Check Point able to provide additional details on this IPS protection?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jul 2022 20:26:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-Transfers-over-port-22-are-failing/m-p/153579#M25778</guid>
      <dc:creator>David_Chau</dc:creator>
      <dc:date>2022-07-21T20:26:17Z</dc:date>
    </item>
    <item>
      <title>Re: File Transfers over port 22 are failing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-Transfers-over-port-22-are-failing/m-p/153604#M25784</link>
      <description>&lt;P&gt;We also see exact these protection hitting on SSH traffic flowing over our gateways from time to time. Could never reproduce it, it just happens from time to time. So I'm also interested about the some background info regarding that protection.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jul 2022 06:51:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-Transfers-over-port-22-are-failing/m-p/153604#M25784</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2022-07-22T06:51:53Z</dc:date>
    </item>
    <item>
      <title>Re: File Transfers over port 22 are failing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-Transfers-over-port-22-are-failing/m-p/153677#M25814</link>
      <description>&lt;P&gt;The Confidence rating of that "&lt;SPAN&gt;Malicious Payload Encoding Remote Code Execution"&amp;nbsp;&lt;/SPAN&gt;protection is Medium, if it were Low I'd be more willing to accept it going off randomly like that.&amp;nbsp; My guess is that this signature is looking for a very short sequence of bytes (&amp;lt;5) without any further context information, and every now and then an encrypted stream happens to match it and get blocked.&amp;nbsp; Seems unlikely but certainly not impossible.&amp;nbsp; Would need to see packet captures of a few separate instances to try to determine what it is seeing that is causing the false positive.&lt;/P&gt;
&lt;P&gt;This vulnerability does not appear to have a CVE number and is something Check Point came up with on their own (CPAI-2013-3606) so only R&amp;amp;D will be able to provide further details.&amp;nbsp; Based on how it is behaving and that multiple posters have seen this behavior, I'd argue that the Confidence level of this protection should be changed to Low.&amp;nbsp; Who knows if this attack method is even relevant anymore; this is an advisory from almost 10 years ago.&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jul 2022 21:07:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/File-Transfers-over-port-22-are-failing/m-p/153677#M25814</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-07-23T21:07:36Z</dc:date>
    </item>
  </channel>
</rss>

