<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SecureXL and SSH in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-and-SSH/m-p/159286#M27862</link>
    <description>&lt;P&gt;We migrated to a pair of 16Ks running VSX. When we created the new VS and launched it successfully, everything works fine but one issue, a user can't ssh to his server when SecureXL is enabled. When it's disabled (fwaccel off) it works and they can SSH. MTU is currently set to 1500.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 11 Oct 2022 19:58:05 GMT</pubDate>
    <dc:creator>mickkel2179</dc:creator>
    <dc:date>2022-10-11T19:58:05Z</dc:date>
    <item>
      <title>SecureXL and SSH</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-and-SSH/m-p/159286#M27862</link>
      <description>&lt;P&gt;We migrated to a pair of 16Ks running VSX. When we created the new VS and launched it successfully, everything works fine but one issue, a user can't ssh to his server when SecureXL is enabled. When it's disabled (fwaccel off) it works and they can SSH. MTU is currently set to 1500.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2022 19:58:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-and-SSH/m-p/159286#M27862</guid>
      <dc:creator>mickkel2179</dc:creator>
      <dc:date>2022-10-11T19:58:05Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL and SSH</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-and-SSH/m-p/159297#M27867</link>
      <description>&lt;P&gt;Hey &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/54621"&gt;@mickkel2179&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can bypass SecureXL for specific connections or ports by following&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104468" target="_blank" rel="noopener"&gt;SK104468&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know this doesn't address the underlying issue, but may act as a temporary workaround whilst you troubleshoot the problem.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2022 21:48:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-and-SSH/m-p/159297#M27867</guid>
      <dc:creator>AaronCP</dc:creator>
      <dc:date>2022-10-11T21:48:02Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL and SSH</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-and-SSH/m-p/159301#M27868</link>
      <description>&lt;P&gt;Which version &amp;amp; JHF is used?&lt;/P&gt;
&lt;P&gt;If disabling secureXL resolves a symptom it's typically a bug and needs to be investigated with TAC.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2022 23:27:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-and-SSH/m-p/159301#M27868</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-10-11T23:27:27Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL and SSH</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-and-SSH/m-p/159354#M27885</link>
      <description>&lt;P&gt;Hey Aaron,&lt;/P&gt;&lt;P&gt;&amp;nbsp;Thanks for the response, really appreciate it! The client has to many IPs to list in order to use this feature. Right now we have a ticket in with R&amp;amp;D .. let's see how that unravels.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 13:13:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-and-SSH/m-p/159354#M27885</guid>
      <dc:creator>mickkel2179</dc:creator>
      <dc:date>2022-10-12T13:13:45Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL and SSH</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-and-SSH/m-p/159355#M27886</link>
      <description>&lt;P&gt;Hey Chris,&lt;/P&gt;&lt;P&gt;&amp;nbsp;The client is on 81.10 335 build and JHF Take 66&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 13:14:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-and-SSH/m-p/159355#M27886</guid>
      <dc:creator>mickkel2179</dc:creator>
      <dc:date>2022-10-12T13:14:29Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL and SSH</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-and-SSH/m-p/159356#M27887</link>
      <description>&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/64803"&gt;@AaronCP&lt;/a&gt;&amp;nbsp;, but as you said, if there are too many IP addresses, then see what R&amp;amp;D says.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 13:26:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-and-SSH/m-p/159356#M27887</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-10-12T13:26:56Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL and SSH</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-and-SSH/m-p/159375#M27891</link>
      <description>&lt;P&gt;You can disable SecureXL (or more accurately prevent templating) for a specific service.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104468&amp;amp;partition=Advanced&amp;amp;product=SecureXL" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104468&amp;amp;partition=Advanced&amp;amp;product=SecureXL&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;Specifically, you'll add the SSH port (22) to the&amp;nbsp;tcp_f2f_ports table.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, as stated by others on this thread, if disabling SecureXL "solves" a problem, it's likely a bug and the TAC should be engaged.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 15:33:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-and-SSH/m-p/159375#M27891</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-12T15:33:14Z</dc:date>
    </item>
  </channel>
</rss>

