<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Failed SSH connection in ClusterXL HA in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-SSH-connection-in-ClusterXL-HA/m-p/196220#M36611</link>
    <description>&lt;P&gt;I have reviewed the basics so far,&lt;/P&gt;
&lt;P&gt;We have a firewall rule that allows SSH connection to ClusterXL HA members.&lt;/P&gt;
&lt;P&gt;We are trying to connect via RA VPN.&lt;/P&gt;
&lt;P&gt;Our RA VPN segment is allowed in the VPN Domain of the RA VPN community, but what I have "noticed" is that when we are connected to the VPN, we do not get the route to manage the 192.168.61.x segment.&lt;/P&gt;
&lt;P&gt;We consult the route table on each PC, with the command "route print".&lt;/P&gt;
&lt;P&gt;In the LOGS nothing is seen (as if no traffic attempt is generated by SSH), and the "FW CTL ZDEBUG + DROP | GREP IP", does not tell us anything wrong.&lt;/P&gt;
&lt;P&gt;Greetings.&lt;/P&gt;</description>
    <pubDate>Thu, 26 Oct 2023 01:02:00 GMT</pubDate>
    <dc:creator>Matlu</dc:creator>
    <dc:date>2023-10-26T01:02:00Z</dc:date>
    <item>
      <title>Failed SSH connection in ClusterXL HA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-SSH-connection-in-ClusterXL-HA/m-p/196218#M36609</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have a curiosity, is there any way to "validate" which port is the one configured to access by SSH to my GW Cluster?&lt;/P&gt;
&lt;P&gt;I have a legacy architecture, I have 2 GW, which its management IP is 192.168.61.2 and 192.168.61.3, but when you try to log in by SSH (Putty, etc), it fails to connect.&lt;/P&gt;
&lt;P&gt;The only way to connect is "jumping" from the SMS, but we want to document why we can not access directly to the GW.&lt;/P&gt;
&lt;P&gt;Maybe they "changed" the SSH port, or simply something is "failing" that does not allow us to connect directly.&lt;/P&gt;
&lt;P&gt;Hopefully someone can give me some troubleshooting tips.&lt;/P&gt;
&lt;P&gt;Thanks. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2023 00:06:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-SSH-connection-in-ClusterXL-HA/m-p/196218#M36609</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-10-26T00:06:32Z</dc:date>
    </item>
    <item>
      <title>Re: Failed SSH connection in ClusterXL HA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-SSH-connection-in-ClusterXL-HA/m-p/196219#M36610</link>
      <description>&lt;P&gt;You can check /etc/ssh/sshd_config file bro.&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2023 00:46:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-SSH-connection-in-ClusterXL-HA/m-p/196219#M36610</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-26T00:46:54Z</dc:date>
    </item>
    <item>
      <title>Re: Failed SSH connection in ClusterXL HA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-SSH-connection-in-ClusterXL-HA/m-p/196220#M36611</link>
      <description>&lt;P&gt;I have reviewed the basics so far,&lt;/P&gt;
&lt;P&gt;We have a firewall rule that allows SSH connection to ClusterXL HA members.&lt;/P&gt;
&lt;P&gt;We are trying to connect via RA VPN.&lt;/P&gt;
&lt;P&gt;Our RA VPN segment is allowed in the VPN Domain of the RA VPN community, but what I have "noticed" is that when we are connected to the VPN, we do not get the route to manage the 192.168.61.x segment.&lt;/P&gt;
&lt;P&gt;We consult the route table on each PC, with the command "route print".&lt;/P&gt;
&lt;P&gt;In the LOGS nothing is seen (as if no traffic attempt is generated by SSH), and the "FW CTL ZDEBUG + DROP | GREP IP", does not tell us anything wrong.&lt;/P&gt;
&lt;P&gt;Greetings.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2023 01:02:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-SSH-connection-in-ClusterXL-HA/m-p/196220#M36611</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-10-26T01:02:00Z</dc:date>
    </item>
    <item>
      <title>Re: Failed SSH connection in ClusterXL HA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-SSH-connection-in-ClusterXL-HA/m-p/196221#M36612</link>
      <description>&lt;P&gt;What does route print show? If such a route is missing on the firewall, then it wont get "injected" when clients connect either.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2023 01:19:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-SSH-connection-in-ClusterXL-HA/m-p/196221#M36612</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-26T01:19:07Z</dc:date>
    </item>
    <item>
      <title>Re: Failed SSH connection in ClusterXL HA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-SSH-connection-in-ClusterXL-HA/m-p/196225#M36613</link>
      <description>&lt;P&gt;We have a rule, where our origin is the segment of the RA VPN connections, and the destination is the GW of the Cluster.&lt;/P&gt;
&lt;P&gt;Destination IPs: 192.168.61.2 and x.x.61.3&lt;/P&gt;
&lt;P&gt;The route print does not show me this segment, for some strange reason.&lt;BR /&gt;I guess that's why we can't reach both GWs, but the strangest thing is that both IPs are within the VPN Domain of the RA VPN community.&lt;/P&gt;
&lt;P&gt;The only way to access the GWs is jumping from the SMS.&lt;/P&gt;
&lt;P&gt;I share a txt with what it shows me at the level of a connected user.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2023 01:48:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-SSH-connection-in-ClusterXL-HA/m-p/196225#M36613</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-10-26T01:48:59Z</dc:date>
    </item>
    <item>
      <title>Re: Failed SSH connection in ClusterXL HA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-SSH-connection-in-ClusterXL-HA/m-p/196228#M36614</link>
      <description>&lt;P&gt;Whats mgmt IP? Can you send route print?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2023 01:52:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-SSH-connection-in-ClusterXL-HA/m-p/196228#M36614</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-26T01:52:14Z</dc:date>
    </item>
    <item>
      <title>Re: Failed SSH connection in ClusterXL HA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-SSH-connection-in-ClusterXL-HA/m-p/196230#M36615</link>
      <description>&lt;P&gt;I share with you the "route print" from a remote user connection.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2023 01:57:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-SSH-connection-in-ClusterXL-HA/m-p/196230#M36615</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-10-26T01:57:44Z</dc:date>
    </item>
    <item>
      <title>Re: Failed SSH connection in ClusterXL HA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-SSH-connection-in-ClusterXL-HA/m-p/196231#M36616</link>
      <description>&lt;P&gt;Routing is your issue, there is nothing for 192.168.61.x subnet. Check proper route exists for it on the cluster.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2023 02:01:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-SSH-connection-in-ClusterXL-HA/m-p/196231#M36616</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-26T02:01:28Z</dc:date>
    </item>
    <item>
      <title>Re: Failed SSH connection in ClusterXL HA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-SSH-connection-in-ClusterXL-HA/m-p/196232#M36617</link>
      <description>&lt;P&gt;To fix the route, from what "perspective", from the same GW of the Cluster?&lt;/P&gt;
&lt;P&gt;Because those IPs, 192.168.61.2 and x.x.x.3, belong to the GWs,&lt;BR /&gt;They are their management IPs.&lt;/P&gt;
&lt;P&gt;You mean validate the route, to reach the network of my VPN remote user connection pool, 192.168.9.0?&lt;/P&gt;
&lt;P&gt;I did not understand that last part of your comment.&lt;/P&gt;
&lt;P&gt;Sorry, Buddy&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2023 02:07:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-SSH-connection-in-ClusterXL-HA/m-p/196232#M36617</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-10-26T02:07:11Z</dc:date>
    </item>
    <item>
      <title>Re: Failed SSH connection in ClusterXL HA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-SSH-connection-in-ClusterXL-HA/m-p/196233#M36618</link>
      <description>&lt;P&gt;The vpn clients are not getting route to that subnet because its not getting propagated from the gateway itself. I would call TAC and do a quick remote for this, Im sure its something simple missing.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2023 02:10:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-SSH-connection-in-ClusterXL-HA/m-p/196233#M36618</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-26T02:10:00Z</dc:date>
    </item>
  </channel>
</rss>

