<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSH version 1.x is not allowed in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-version-1-x-is-not-allowed/m-p/225530#M43399</link>
    <description>&lt;P&gt;This is what I've done.&amp;nbsp; I created a TCP service for port 2200, and did not select any protocol from the drop down menu.&amp;nbsp; Configuring in this way was not sufficient to allow this traffic.&amp;nbsp; I do get matches for "Accepted" but then a "Reject" right after it saying the version 1.x is not allowed message.&lt;/P&gt;</description>
    <pubDate>Tue, 03 Sep 2024 17:32:34 GMT</pubDate>
    <dc:creator>Cypress</dc:creator>
    <dc:date>2024-09-03T17:32:34Z</dc:date>
    <item>
      <title>SSH version 1.x is not allowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-version-1-x-is-not-allowed/m-p/225525#M43395</link>
      <description>&lt;P&gt;Hello.&amp;nbsp; We are implementing a test environment currently, so new gateways and a new policy... and I'm running into a traffic Reject I haven't encountered before.&amp;nbsp; The Reject shows as Blade: Firewall, and has no matching rule number, and for message information it says "SSH version 1.x is not allowed."&lt;/P&gt;&lt;P&gt;I have Googled for this specific message, and found&amp;nbsp;sk30470.. unfortunately the solution provided in&amp;nbsp;sk30470 doesn't seem to work for me!&lt;/P&gt;&lt;P&gt;The traffic being Rejected by Check Point is for a Juniper Networks EX-series network switch talking to "MIST Wired Assurance" cloud management platform on TCP/2200.&lt;/P&gt;&lt;P&gt;The Check Point gateway is Rejecting this traffic because "SSH version 1.x is not allowed."&amp;nbsp; Ok, that is not ideal if MIST is truly using that protocol version, and that's something I can bring up with that vendor.. but in the mean time, I really have to be able to allow this traffic on the Gateway.&amp;nbsp; The problem is, I cannot figure out how!&amp;nbsp; The article sk30470 says to use the 'ssh' service object to match all versions of ssh, but this traffic is using a custom port 2200.&amp;nbsp; So.. how do I work around this issue?&amp;nbsp; When I Created a custom service object to match TCP/2200, I only see ssh2 in the drop down for protocols.&lt;/P&gt;&lt;P&gt;Is this something I have to make an exception for in Inspection Settings?&amp;nbsp; In the past I have done an exception like "Non-HTTPS Traffic over an HTTPS port" but there doesn't seem to be a similar option for SSH version 1.x is not allowed."&lt;/P&gt;&lt;P&gt;Any help would be appreciated.&amp;nbsp; Since this for a test gateway I do not feel it warrants a TAC case, but I haven't been able to figure this out yet...&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2024 17:08:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-version-1-x-is-not-allowed/m-p/225525#M43395</guid>
      <dc:creator>Cypress</dc:creator>
      <dc:date>2024-09-03T17:08:45Z</dc:date>
    </item>
    <item>
      <title>Re: SSH version 1.x is not allowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-version-1-x-is-not-allowed/m-p/225526#M43396</link>
      <description>&lt;P&gt;As soon as I started reading your post, inspection settings came to mind. Though, out of the box, setting is default, NOT recommended, but will have a look at the lab later to see whats there for ssh.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2024 17:21:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-version-1-x-is-not-allowed/m-p/225526#M43396</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-03T17:21:06Z</dc:date>
    </item>
    <item>
      <title>Re: SSH version 1.x is not allowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-version-1-x-is-not-allowed/m-p/225527#M43397</link>
      <description>&lt;P&gt;How does the rule look? Traffic hits now ''any'' services? If so try to make a custom TCP-2200 port and allow it with that.&lt;/P&gt;
&lt;P&gt;Also app blade enabled?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can also try to clone the default SSH services and change the port&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2024 17:23:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-version-1-x-is-not-allowed/m-p/225527#M43397</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-09-03T17:23:21Z</dc:date>
    </item>
    <item>
      <title>Re: SSH version 1.x is not allowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-version-1-x-is-not-allowed/m-p/225528#M43398</link>
      <description>&lt;P&gt;Why not create a simple TCP service without a protocol handler for ssh?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2024 17:24:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-version-1-x-is-not-allowed/m-p/225528#M43398</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-09-03T17:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: SSH version 1.x is not allowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-version-1-x-is-not-allowed/m-p/225530#M43399</link>
      <description>&lt;P&gt;This is what I've done.&amp;nbsp; I created a TCP service for port 2200, and did not select any protocol from the drop down menu.&amp;nbsp; Configuring in this way was not sufficient to allow this traffic.&amp;nbsp; I do get matches for "Accepted" but then a "Reject" right after it saying the version 1.x is not allowed message.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2024 17:32:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-version-1-x-is-not-allowed/m-p/225530#M43399</guid>
      <dc:creator>Cypress</dc:creator>
      <dc:date>2024-09-03T17:32:34Z</dc:date>
    </item>
    <item>
      <title>Re: SSH version 1.x is not allowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-version-1-x-is-not-allowed/m-p/225531#M43400</link>
      <description>&lt;P&gt;I will give this a try cloning the ssh service and changing the port.&lt;/P&gt;&lt;P&gt;EDIT: This appears to have done the trick.&amp;nbsp; Clone default ssh service and rename ssh_mist and changed the port to 2200 and now I am no longer seeing "Reject" in the logs.&amp;nbsp; And both lab switches lit up green in my Mist console.&amp;nbsp; (They were showing Red/Disconnected before)&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2024 19:09:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-version-1-x-is-not-allowed/m-p/225531#M43400</guid>
      <dc:creator>Cypress</dc:creator>
      <dc:date>2024-09-03T19:09:35Z</dc:date>
    </item>
    <item>
      <title>Re: SSH version 1.x is not allowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-version-1-x-is-not-allowed/m-p/225532#M43401</link>
      <description>&lt;P&gt;Would you mind send us a screenthot? Just please blur out any sensitive info. Btw, I did check in my lab and though my gateways are set to recommended inspection profile, there is absolutely nothing referenced for ssh.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2024 17:47:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-version-1-x-is-not-allowed/m-p/225532#M43401</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-03T17:47:02Z</dc:date>
    </item>
    <item>
      <title>Re: SSH version 1.x is not allowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-version-1-x-is-not-allowed/m-p/225540#M43402</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="ssh_not_allowed.JPG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27487iAA3234967DE3D4BA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ssh_not_allowed.JPG" alt="ssh_not_allowed.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This screenshot shows the accept immediately followed by the reject.&amp;nbsp; The accept matches the expected rule number and rule name, while the reject is blank for rule number/rule name.&amp;nbsp; It's the blankness that confuses me.. what is blocking it?&amp;nbsp; It is coming from the firewall blade but it's not an actual "rule block'&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2024 19:07:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-version-1-x-is-not-allowed/m-p/225540#M43402</guid>
      <dc:creator>Cypress</dc:creator>
      <dc:date>2024-09-03T19:07:12Z</dc:date>
    </item>
    <item>
      <title>Re: SSH version 1.x is not allowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-version-1-x-is-not-allowed/m-p/225541#M43403</link>
      <description>&lt;P&gt;Does it give more info if you double click on it?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2024 19:09:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-version-1-x-is-not-allowed/m-p/225541#M43403</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-03T19:09:12Z</dc:date>
    </item>
    <item>
      <title>Re: SSH version 1.x is not allowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-version-1-x-is-not-allowed/m-p/225551#M43405</link>
      <description>&lt;P&gt;Lesleyy's suggestion of clone the default ssh service and change its port has fixed this issue.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2024 21:27:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-version-1-x-is-not-allowed/m-p/225551#M43405</guid>
      <dc:creator>Cypress</dc:creator>
      <dc:date>2024-09-03T21:27:34Z</dc:date>
    </item>
    <item>
      <title>Re: SSH version 1.x is not allowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-version-1-x-is-not-allowed/m-p/225554#M43406</link>
      <description>&lt;P&gt;Great!&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2024 22:23:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-version-1-x-is-not-allowed/m-p/225554#M43406</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-03T22:23:45Z</dc:date>
    </item>
  </channel>
</rss>

