<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ssh access issues in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/ssh-access-issues/m-p/123301#M22809</link>
    <description>&lt;P&gt;Sounds like the Gaia OS is "eating" the packet, if you run &lt;STRONG&gt;fw monitor&lt;/STRONG&gt; do you see the packet at capture points iI then nothing else?&lt;/P&gt;
&lt;P&gt;In the Gaia web interface check the Allowed Hosts screen under System Management...Host Access, you probably have some Gaia-based SSH/HTTPS restrictions defined there.&lt;/P&gt;</description>
    <pubDate>Thu, 08 Jul 2021 12:10:47 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2021-07-08T12:10:47Z</dc:date>
    <item>
      <title>ssh access issues</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ssh-access-issues/m-p/123263#M22802</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a strange challenge on a cluster. SSH access from a specific jump host is not working.&lt;/P&gt;&lt;P&gt;tcpdump shows that the fw receives the syn packet, but doesnt send any replies back. Smartconsole logs also show that the request is accepted, and there are no antispoofing issues.&lt;/P&gt;&lt;P&gt;i can access the fw on ssh from another location, which kinda adds to the whole mystery.&lt;/P&gt;&lt;P&gt;there is nothing logged when running zdebug drop, so for all intent and purposes, the packet is received, then "vanishes" after that.&lt;/P&gt;&lt;P&gt;Anyone seen anything similar before?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jul 2021 06:59:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ssh-access-issues/m-p/123263#M22802</guid>
      <dc:creator>KM1895</dc:creator>
      <dc:date>2021-07-08T06:59:13Z</dc:date>
    </item>
    <item>
      <title>Re: ssh access issues</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ssh-access-issues/m-p/123301#M22809</link>
      <description>&lt;P&gt;Sounds like the Gaia OS is "eating" the packet, if you run &lt;STRONG&gt;fw monitor&lt;/STRONG&gt; do you see the packet at capture points iI then nothing else?&lt;/P&gt;
&lt;P&gt;In the Gaia web interface check the Allowed Hosts screen under System Management...Host Access, you probably have some Gaia-based SSH/HTTPS restrictions defined there.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jul 2021 12:10:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ssh-access-issues/m-p/123301#M22809</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-07-08T12:10:47Z</dc:date>
    </item>
    <item>
      <title>Re: ssh access issues</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ssh-access-issues/m-p/123335#M22817</link>
      <description>&lt;P&gt;Timothy actually brought up a good point...maybe do fw monitor to see what happens. Allowed Hosts in web GUI could also cause an issue if configured for specific hosts.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jul 2021 14:28:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ssh-access-issues/m-p/123335#M22817</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-07-08T14:28:34Z</dc:date>
    </item>
    <item>
      <title>Re: ssh access issues</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ssh-access-issues/m-p/123345#M22819</link>
      <description>&lt;P&gt;Yes and because the SSH traffic is to the gateway itself, that traffic will always go F2F so no need to disable SecureXL for the traffic to be visible with&amp;nbsp;&lt;STRONG&gt;fw monitor -e&lt;/STRONG&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jul 2021 14:58:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ssh-access-issues/m-p/123345#M22819</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-07-08T14:58:42Z</dc:date>
    </item>
    <item>
      <title>Re: ssh access issues</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ssh-access-issues/m-p/123382#M22826</link>
      <description>&lt;P&gt;Would also be worth confirming routing back to the jump host in question. It's possible the firewall&amp;nbsp;&lt;EM&gt;is&lt;/EM&gt; sending the SYN-ACK, just out a different interface than expected. The simplest way to confirm routing is with 'ip route get', like so:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[Expert@LabSC]# ip route get 1.1.1.1
1.1.1.1 via 10.0.1.1 dev eth1 src 10.0.1.253 
    cache &lt;/LI-CODE&gt;
&lt;P&gt;That output says I will use eth1 to get to that destination, and I will use the gateway address 10.0.1.1. My source for transmitted traffic will be 10.0.1.253.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jul 2021 19:06:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ssh-access-issues/m-p/123382#M22826</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2021-07-08T19:06:42Z</dc:date>
    </item>
  </channel>
</rss>

