<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSH Inspection in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/214240#M40894</link>
    <description>&lt;P&gt;Well, that's a start.&lt;/P&gt;
&lt;P&gt;The best way to confirm is via telnet to port 22 to the protected server.&lt;BR /&gt;This (along with troubleshooting) is listed at the bottom of the documentation linked earlier in this thread.&lt;/P&gt;</description>
    <pubDate>Tue, 14 May 2024 22:02:56 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-05-14T22:02:56Z</dc:date>
    <item>
      <title>SSH Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/210171#M39825</link>
      <description>&lt;P&gt;Hello friends!&lt;BR /&gt;I am currently looking into implemnting ssh inspection feature for the checkpoint security gateway, and I was unable to find a lot of information or guides on this feature (except the two minimal guides on the checkpoint site) so I would be glad if someone can point me to a more comprehensive guide or document, or maybe answer some of my questions regarding this feature -&amp;nbsp; the ssh client needs to ssh to the security gateway or to the ssh server (and the session just passes the security gateway)?&lt;BR /&gt;&lt;BR /&gt;Thanks in advance:)&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2024 12:58:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/210171#M39825</guid>
      <dc:creator>bob111</dc:creator>
      <dc:date>2024-04-01T12:58:35Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/210172#M39826</link>
      <description>&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_ThreatPrevention_AdminGuide/Topics-TPG/Using-SSH-Inspection.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_ThreatPrevention_AdminGuide/Topics-TPG/Using-SSH-Inspection.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2024 13:26:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/210172#M39826</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-01T13:26:37Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/210185#M39829</link>
      <description>&lt;P&gt;The only resource for SSH Deep Packet Inspection is the one&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;provided in the formal documentation.&amp;nbsp; Most people aren't even aware this feature exists since it can't be configured in the SmartConsole GUI.&amp;nbsp; You may also see references to "RDP Inspection" if you look around in the documentation hard enough; this feature had a very short lifespan and is no longer present.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2024 14:40:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/210185#M39829</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-04-01T14:40:56Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/210187#M39831</link>
      <description>&lt;P&gt;Thank you very much for the replies!&amp;nbsp;&lt;BR /&gt;What do you mean by "no longer present"?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2024 14:59:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/210187#M39831</guid>
      <dc:creator>bob111</dc:creator>
      <dc:date>2024-04-01T14:59:53Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/210188#M39832</link>
      <description>&lt;P&gt;Maybe you can confirm with TAC if they have any other additional info about it.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2024 15:18:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/210188#M39832</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-01T15:18:53Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/210606#M39901</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;, did you mean that ssh inspection is a feature that is no longer present or rdp inspection?&lt;/P&gt;</description>
      <pubDate>Sun, 07 Apr 2024 11:15:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/210606#M39901</guid>
      <dc:creator>ww1m6</dc:creator>
      <dc:date>2024-04-07T11:15:07Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/210609#M39902</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;,&amp;nbsp; The ssh inspection feature had a very short lifespan and is no longer present or the rdp inspection?&lt;/P&gt;</description>
      <pubDate>Sun, 07 Apr 2024 12:58:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/210609#M39902</guid>
      <dc:creator>ww1m6</dc:creator>
      <dc:date>2024-04-07T12:58:39Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/210610#M39903</link>
      <description>&lt;P&gt;RDP Inspection is no longer present.&amp;nbsp; See here:&amp;nbsp;&lt;A id="link_12" href="https://community.checkpoint.com/t5/Security-Gateways/Remote-Desktop-Inspection-Still-Supported/m-p/178816?search-action-id=86009946178&amp;amp;search-result-uid=178816" target="_blank"&gt;Remote Desktop&amp;nbsp;Inspection&amp;nbsp;Still Supported?&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 07 Apr 2024 13:20:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/210610#M39903</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-04-07T13:20:06Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/210614#M39904</link>
      <description>&lt;P&gt;ssh inspection is still supported, but rdp inspection is not, as per link Tim sent.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 07 Apr 2024 13:42:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/210614#M39904</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-07T13:42:34Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/211490#M40090</link>
      <description>&lt;P&gt;Once ssh inspection is turned on (ion), does that mean all current ssh traffic going thru the gw will break until you add all the public and private keys to the gw?&amp;nbsp; With 'https inspection', you can bypass traffic you don't want inspected.&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 20:43:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/211490#M40090</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2024-04-16T20:43:20Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/211500#M40093</link>
      <description>&lt;P&gt;If I'm understanding the documentation correctly, we are only inspecting SSH connections where the public (and private) key is added to the gateway.&lt;BR /&gt;However, I haven't tested this.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 21:40:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/211500#M40093</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-04-16T21:40:29Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/213942#M40816</link>
      <description>&lt;P&gt;You need to add the private key to the gateway? The documentation says you only need to add the public key&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 May 2024 12:40:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/213942#M40816</guid>
      <dc:creator>ww1m6</dc:creator>
      <dc:date>2024-05-12T12:40:11Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/214050#M40861</link>
      <description>&lt;P&gt;You&amp;nbsp;&lt;EM&gt;can&lt;/EM&gt; add the private key to improve the user experience, but it's not a requirement.&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2024 15:14:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/214050#M40861</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-05-13T15:14:32Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/214052#M40862</link>
      <description>&lt;P&gt;I understand. I followed&amp;nbsp; the guide for configuring the ssh inspection but where can I actually see that the ssh traffic to the ssh server that it's key I added to the gateway is being inspected?&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2024 15:18:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/214052#M40862</guid>
      <dc:creator>ww1m6</dc:creator>
      <dc:date>2024-05-13T15:18:52Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/214211#M40886</link>
      <description>&lt;P&gt;What does&amp;nbsp;cpssh_config istatus tell you?&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2024 17:16:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/214211#M40886</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-05-14T17:16:59Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/214213#M40887</link>
      <description>&lt;P&gt;Man, learn something new from you all the time, I never knew of that command before &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2024 17:19:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/214213#M40887</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-14T17:19:17Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/214215#M40888</link>
      <description>&lt;P&gt;SSH Inspection is enabled&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2024 17:24:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/214215#M40888</guid>
      <dc:creator>ww1m6</dc:creator>
      <dc:date>2024-05-14T17:24:02Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/214240#M40894</link>
      <description>&lt;P&gt;Well, that's a start.&lt;/P&gt;
&lt;P&gt;The best way to confirm is via telnet to port 22 to the protected server.&lt;BR /&gt;This (along with troubleshooting) is listed at the bottom of the documentation linked earlier in this thread.&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2024 22:02:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/214240#M40894</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-05-14T22:02:56Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/214358#M40913</link>
      <description>&lt;P&gt;Yes, I tried it but I did not get the result shown in the documentation. Am I supposed to be able to see the ssh traffic inspected in the logs on the management server?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 13:21:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/214358#M40913</guid>
      <dc:creator>ww1m6</dc:creator>
      <dc:date>2024-05-15T13:21:29Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/214619#M40974</link>
      <description>&lt;P&gt;If it's not showing the Check Point specific SSH banner, then it's not doing inspection.&lt;BR /&gt;Recommend engaging with TAC for further assistance: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2024 02:13:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-Inspection/m-p/214619#M40974</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-05-17T02:13:57Z</dc:date>
    </item>
  </channel>
</rss>

