<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic No ssh access to VPN peer outside IP in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/No-ssh-access-to-VPN-peer-outside-IP/m-p/17904#M3064</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;While testing a site-to-site VPN tunnel between CP80.10 and Cisco ASA, I noticed that right after I had configured the IPSec peer on CP80.10, I was no longer able to ssh to 10.0.14.101 (ASA outside IP) to manage the device. Then I looked into the logs on CP and found out that CP80.10 is trying to encrypt packets destined to ASA outside IP address 10.0.14.101. I wasn't able to find any info about this issue. Is there any way how I can disable or turn off this behavior? Screenshot of the logs in the attachment. Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 24 Apr 2018 13:51:38 GMT</pubDate>
    <dc:creator>Vlad_Voronko</dc:creator>
    <dc:date>2018-04-24T13:51:38Z</dc:date>
    <item>
      <title>No ssh access to VPN peer outside IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/No-ssh-access-to-VPN-peer-outside-IP/m-p/17904#M3064</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;While testing a site-to-site VPN tunnel between CP80.10 and Cisco ASA, I noticed that right after I had configured the IPSec peer on CP80.10, I was no longer able to ssh to 10.0.14.101 (ASA outside IP) to manage the device. Then I looked into the logs on CP and found out that CP80.10 is trying to encrypt packets destined to ASA outside IP address 10.0.14.101. I wasn't able to find any info about this issue. Is there any way how I can disable or turn off this behavior? Screenshot of the logs in the attachment. Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Apr 2018 13:51:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/No-ssh-access-to-VPN-peer-outside-IP/m-p/17904#M3064</guid>
      <dc:creator>Vlad_Voronko</dc:creator>
      <dc:date>2018-04-24T13:51:38Z</dc:date>
    </item>
    <item>
      <title>Re: No ssh access to VPN peer outside IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/No-ssh-access-to-VPN-peer-outside-IP/m-p/17905#M3065</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;quick way to solve it ? use excluded service and add ssh there , definition ip of the remote peer is part of the remote enc domain &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Apr 2018 13:58:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/No-ssh-access-to-VPN-peer-outside-IP/m-p/17905#M3065</guid>
      <dc:creator>Marco_Valenti</dc:creator>
      <dc:date>2018-04-24T13:58:28Z</dc:date>
    </item>
    <item>
      <title>Re: No ssh access to VPN peer outside IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/No-ssh-access-to-VPN-peer-outside-IP/m-p/17906#M3066</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Marco,&lt;/P&gt;&lt;P&gt;I considered that option but I guess enabling it would prevent me from establishing an ssh session to the equipment residing behind the ASA (which only reachable over the VPN tunnel).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Apr 2018 14:11:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/No-ssh-access-to-VPN-peer-outside-IP/m-p/17906#M3066</guid>
      <dc:creator>Vlad_Voronko</dc:creator>
      <dc:date>2018-04-24T14:11:53Z</dc:date>
    </item>
    <item>
      <title>Re: No ssh access to VPN peer outside IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/No-ssh-access-to-VPN-peer-outside-IP/m-p/17907#M3067</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sk108600 Scenario 3 -&amp;nbsp;Implied inclusion of Check Point Security Gateway's / 3rd party VPN Peer's interfaces&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Apr 2018 14:17:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/No-ssh-access-to-VPN-peer-outside-IP/m-p/17907#M3067</guid>
      <dc:creator>Brandon_Pace</dc:creator>
      <dc:date>2018-04-24T14:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: No ssh access to VPN peer outside IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/No-ssh-access-to-VPN-peer-outside-IP/m-p/17908#M3068</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would suggest to consult &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk25675&amp;amp;partition=Advanced&amp;amp;product=IPSec"&gt;&lt;EM&gt;sk25675 Customizing VPN Domain to exclude IP Address and allow clear text&lt;/EM&gt;&lt;/A&gt; and &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108600&amp;amp;partition=Advanced&amp;amp;product=IPSec#Scenario%203"&gt;&lt;EM&gt;sk108600 VPN Site-to-Site with 3rd party Scenario 3&lt;/EM&gt;&lt;/A&gt; !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Apr 2018 14:18:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/No-ssh-access-to-VPN-peer-outside-IP/m-p/17908#M3068</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-04-24T14:18:16Z</dc:date>
    </item>
    <item>
      <title>Re: No ssh access to VPN peer outside IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/No-ssh-access-to-VPN-peer-outside-IP/m-p/17909#M3069</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A _jive_internal="true" data-userid="54845" data-username="g.alba066e051-da82-3e7a-84e6-2bcbff226984" href="https://community.checkpoint.com/people/g.alba066e051-da82-3e7a-84e6-2bcbff226984" style="color: #e45785; background-color: #ffffff; border: 0px; font-weight: 200; text-decoration: none; font-size: 1.286rem;"&gt;Günther&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A _jive_internal="true" class="" data-userid="50299" data-username="bpace29eed499-8758-4115-b4e7-7e83e5555fcf" href="https://community.checkpoint.com/people/bpace29eed499-8758-4115-b4e7-7e83e5555fcf" style="color: #e45785; background-color: #ffffff; border: 0px; font-weight: 200; text-decoration: underline; font-size: 1.286rem;"&gt;Brandon&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;Thanks a lot I'll take a look into this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Apr 2018 14:26:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/No-ssh-access-to-VPN-peer-outside-IP/m-p/17909#M3069</guid>
      <dc:creator>Vlad_Voronko</dc:creator>
      <dc:date>2018-04-24T14:26:33Z</dc:date>
    </item>
    <item>
      <title>Re: No ssh access to VPN peer outside IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/No-ssh-access-to-VPN-peer-outside-IP/m-p/17910#M3070</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&lt;A _jive_internal="true" class="" data-containerid="-1" data-containertype="-1" data-objectid="50299" data-objecttype="3" href="https://community.checkpoint.com/people/bpace29eed499-8758-4115-b4e7-7e83e5555fcf" style="color: #e45785; background-color: #ffffff; border: 0px; font-weight: 200; font-size: 1.286rem; padding: 1px 0px 1px calc(12px + 0.35ex);"&gt;Brandon&lt;/A&gt;,&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;Thanks a lot I'll take a look into this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Apr 2018 14:27:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/No-ssh-access-to-VPN-peer-outside-IP/m-p/17910#M3070</guid>
      <dc:creator>Vlad_Voronko</dc:creator>
      <dc:date>2018-04-24T14:27:32Z</dc:date>
    </item>
    <item>
      <title>Re: No ssh access to VPN peer outside IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/No-ssh-access-to-VPN-peer-outside-IP/m-p/17911#M3071</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class=""&gt;Did you try to exclude ssh in the vpn community? And then push policy?&lt;/P&gt;&lt;P class=""&gt;Of course if you need to use ssh on Remote encryption domain, that might be a challange.&lt;/P&gt;&lt;P class=""&gt;&lt;BR /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Apr 2018 04:57:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/No-ssh-access-to-VPN-peer-outside-IP/m-p/17911#M3071</guid>
      <dc:creator>Kim_Moberg</dc:creator>
      <dc:date>2018-04-25T04:57:18Z</dc:date>
    </item>
    <item>
      <title>Re: No ssh access to VPN peer outside IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/No-ssh-access-to-VPN-peer-outside-IP/m-p/113493#M21283</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;What about on Scalable Platforms (Maestro). SMS is R80.40 and GW is R80.30SP.&lt;/P&gt;&lt;P&gt;I've tried to edit crypt.def file on Management and GW as well. But still no success.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Before I used to this SK and it works perfect and SMS, GW both were the same version..&lt;/P&gt;&lt;P&gt;&amp;nbsp;Do you have any clue?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Mar 2021 08:40:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/No-ssh-access-to-VPN-peer-outside-IP/m-p/113493#M21283</guid>
      <dc:creator>Gomboragchaa</dc:creator>
      <dc:date>2021-03-15T08:40:39Z</dc:date>
    </item>
    <item>
      <title>Re: No ssh access to VPN peer outside IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/No-ssh-access-to-VPN-peer-outside-IP/m-p/113515#M21284</link>
      <description>&lt;P&gt;Three hints:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- The "&lt;/SPAN&gt;&lt;CODE&gt;crypt.def&lt;/CODE&gt;&lt;SPAN&gt;" file has to be edited only on Security Management Server. The relevant code will be transferred to Security Gateway during policy installation. (sk98241)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-&amp;nbsp;The "&lt;CODE&gt;crypt.def&lt;/CODE&gt;" file has to be edited in plain-text editor (Vi on Unix-based OS ; Notepad/Notepad++ on Windows OS).&amp;nbsp; (sk98241)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- R80.30SP should be included when&amp;nbsp;$FWDIR/lib/crypt.def is edited and the policy installed.&amp;nbsp;(sk98241)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If all these have been followed i would contact TAC !&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Mar 2021 09:41:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/No-ssh-access-to-VPN-peer-outside-IP/m-p/113515#M21284</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-03-15T09:41:08Z</dc:date>
    </item>
  </channel>
</rss>

