<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MHO140 disabled ssh cipher in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/MHO140-disabled-ssh-cipher/m-p/151635#M996</link>
    <description>&lt;P&gt;Hi Kobil,&lt;/P&gt;&lt;P&gt;I didn't try this new command before installing any JHF.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Todd&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 23 Jun 2022 15:55:17 GMT</pubDate>
    <dc:creator>todd</dc:creator>
    <dc:date>2022-06-23T15:55:17Z</dc:date>
    <item>
      <title>MHO140 disabled ssh cipher</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/MHO140-disabled-ssh-cipher/m-p/150086#M932</link>
      <description>&lt;P&gt;Hi Expert,&lt;/P&gt;&lt;P&gt;Our client is asking us to disable ssh cipher cbc. We tried to use new feature started from R81.10 to disable it.&lt;/P&gt;&lt;P&gt;SMS and gateway running R81.10 are all work fine with this new feature and very easy to configure it.&lt;/P&gt;&lt;P&gt;But MHO140( R81.10SP JHF30 ) doesn't work as expected.&amp;nbsp; Without any modification, there is no cipher enabled in the list. So we don't know which cipher is enabled currently.&lt;/P&gt;&lt;P&gt;Any suggestions ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;MHO-140-1&amp;gt; show ssh server cipher supported&lt;BR /&gt;--------------------------------&lt;BR /&gt;supported cipher:&lt;BR /&gt;--------------------------------&lt;BR /&gt;3des-cbc&lt;BR /&gt;aes128-cbc&lt;BR /&gt;aes128-ctr&lt;BR /&gt;aes128-gcm@openssh.com&lt;BR /&gt;aes192-cbc&lt;BR /&gt;aes192-ctr&lt;BR /&gt;aes256-cbc&lt;BR /&gt;aes256-ctr&lt;BR /&gt;aes256-gcm@openssh.com&lt;BR /&gt;chacha20-poly1305@openssh.com&lt;BR /&gt;rijndael-cbc@lysator.liu.se&lt;BR /&gt;--------------------------------&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;MHO-140-1&amp;gt; show ssh server cipher enabled&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;--------------------------------&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;enabled cipher:&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;--------------------------------&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;--------------------------------&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jun 2022 06:04:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/MHO140-disabled-ssh-cipher/m-p/150086#M932</guid>
      <dc:creator>todd</dc:creator>
      <dc:date>2022-06-03T06:04:55Z</dc:date>
    </item>
    <item>
      <title>Re: MHO140 disabled ssh cipher</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/MHO140-disabled-ssh-cipher/m-p/151389#M958</link>
      <description>&lt;P&gt;We just noticed this as well.&amp;nbsp; R81.10 Jumbo #55 (but maybe before as well) on upgraded Gateways we cannot set it or see what is supported or enabled.&amp;nbsp; Yet it seems to work on our fresh installed Gateways.&amp;nbsp; At least the few I have looked at so far.&lt;/P&gt;&lt;P&gt;The command is there but gives the error "invalid cipher" or "invalid mac"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 18:49:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/MHO140-disabled-ssh-cipher/m-p/151389#M958</guid>
      <dc:creator>ptuttle_2</dc:creator>
      <dc:date>2022-06-21T18:49:11Z</dc:date>
    </item>
    <item>
      <title>Re: MHO140 disabled ssh cipher</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/MHO140-disabled-ssh-cipher/m-p/151472#M977</link>
      <description>&lt;P&gt;Hi todd, do you know if this issue was observed before installing JHF?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 13:38:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/MHO140-disabled-ssh-cipher/m-p/151472#M977</guid>
      <dc:creator>kobil</dc:creator>
      <dc:date>2022-06-22T13:38:09Z</dc:date>
    </item>
    <item>
      <title>Re: MHO140 disabled ssh cipher</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/MHO140-disabled-ssh-cipher/m-p/151635#M996</link>
      <description>&lt;P&gt;Hi Kobil,&lt;/P&gt;&lt;P&gt;I didn't try this new command before installing any JHF.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Todd&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2022 15:55:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/MHO140-disabled-ssh-cipher/m-p/151635#M996</guid>
      <dc:creator>todd</dc:creator>
      <dc:date>2022-06-23T15:55:17Z</dc:date>
    </item>
    <item>
      <title>Re: MHO140 disabled ssh cipher</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/MHO140-disabled-ssh-cipher/m-p/160953#M1241</link>
      <description>&lt;P&gt;working with JHF78, is there a command to remove the -cbc ciphers?&amp;nbsp; delete ssh ... that's as far as it goes&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;mgmt1&amp;gt; show ssh server cipher supported&lt;BR /&gt;--------------------------------&lt;BR /&gt;supported cipher:&lt;BR /&gt;--------------------------------&lt;BR /&gt;3des-cbc&lt;BR /&gt;aes128-cbc&lt;BR /&gt;aes128-ctr&lt;BR /&gt;aes128-gcm@openssh.com&lt;BR /&gt;aes192-cbc&lt;BR /&gt;aes192-ctr&lt;BR /&gt;aes256-cbc&lt;BR /&gt;aes256-ctr&lt;BR /&gt;aes256-gcm@openssh.com&lt;BR /&gt;chacha20-poly1305@openssh.com&lt;BR /&gt;rijndael-cbc@lysator.liu.se&lt;/P&gt;</description>
      <pubDate>Tue, 01 Nov 2022 20:02:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/MHO140-disabled-ssh-cipher/m-p/160953#M1241</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2022-11-01T20:02:04Z</dc:date>
    </item>
  </channel>
</rss>

