<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can Outbound SSH be Secured? in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Can-Outbound-SSH-be-Secured/m-p/65942#M13489</link>
    <description>Here's what I wrote a few years ago on this topic, which is still valid advice: &lt;A href="http://phoneboy.org/2015/07/30/the-right-way-to-inspect-ssh-connections/" target="_blank"&gt;http://phoneboy.org/2015/07/30/the-right-way-to-inspect-ssh-connections/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;It's worth noting that Check Point is planning to support inbound SSH inspection in R80.40, with outbound SSH inspection on the roadmap.</description>
    <pubDate>Fri, 25 Oct 2019 17:43:10 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2019-10-25T17:43:10Z</dc:date>
    <item>
      <title>Can Outbound SSH be Secured?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Can-Outbound-SSH-be-Secured/m-p/65941#M13488</link>
      <description>&lt;P&gt;With the proliferation of cloud services being used by both our customers and partners, we are getting dramatically increased pressure to allow outbound (internally initialed) SSH access between our company and these various customer and partner systems that are running on cloud services. We have no issue with using SSH for terminal access, but are concerned because of how SSH can be used to tunnel traffic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I understand that what makes SSH problematic to inspect is that it’s based on self-signed certificates, rather than PKI, so you can’t do decryption inspection like you can with a typical browser/HTTP access.&lt;/P&gt;&lt;P&gt;Are others in this community facing this same dilemma?&amp;nbsp; Should we be overly concerned about this? What are some ways that we can provide the access that is being requested as securely as possible?&lt;/P&gt;&lt;P&gt;I would appreciate any and all suggestions... whether or not this advice is purely based on CheckPoint policy/configuration or some other solution.&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2019 17:32:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Can-Outbound-SSH-be-Secured/m-p/65941#M13488</guid>
      <dc:creator>Mike_Schepers</dc:creator>
      <dc:date>2019-10-25T17:32:56Z</dc:date>
    </item>
    <item>
      <title>Re: Can Outbound SSH be Secured?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Can-Outbound-SSH-be-Secured/m-p/65942#M13489</link>
      <description>Here's what I wrote a few years ago on this topic, which is still valid advice: &lt;A href="http://phoneboy.org/2015/07/30/the-right-way-to-inspect-ssh-connections/" target="_blank"&gt;http://phoneboy.org/2015/07/30/the-right-way-to-inspect-ssh-connections/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;It's worth noting that Check Point is planning to support inbound SSH inspection in R80.40, with outbound SSH inspection on the roadmap.</description>
      <pubDate>Fri, 25 Oct 2019 17:43:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Can-Outbound-SSH-be-Secured/m-p/65942#M13489</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-10-25T17:43:10Z</dc:date>
    </item>
    <item>
      <title>Re: Can Outbound SSH be Secured?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Can-Outbound-SSH-be-Secured/m-p/127425#M23312</link>
      <description>&lt;P&gt;Sorry to bump such an old thread but SSH Deep Packet Inspection was introduced in R80.40+ and is documented in the R80.40+ Threat Prevention Administration Guide.&amp;nbsp; It is a CLI-based setup and not configured from the SmartConsole, even as of R81.10.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Aug 2021 14:30:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Can-Outbound-SSH-be-Secured/m-p/127425#M23312</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-08-19T14:30:59Z</dc:date>
    </item>
  </channel>
</rss>

