<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R81.20.05+ - SSH traffic is excluded from VPN in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R81-20-05-SSH-traffic-is-excluded-from-VPN/m-p/194791#M9597</link>
    <description>&lt;P&gt;Thanks for letting us know.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Wed, 11 Oct 2023 11:59:30 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-10-11T11:59:30Z</dc:date>
    <item>
      <title>R81.20.05+ - SSH traffic is excluded from VPN</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R81-20-05-SSH-traffic-is-excluded-from-VPN/m-p/194675#M9586</link>
      <description>&lt;P&gt;As from R81.10.05, it seems SSH and SFTP (TCP/22) traffic originating from the gateway itself to a server behind a VPN tunnel is not put in the tunnel but sent out according to the routing table. Not sure what is causing this behavior, I do not find something in the release notes. Any ideas ?&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;All firewalls are centrally managed.&lt;/LI&gt;&lt;LI&gt;SSH is not excluded from VPN.&lt;/LI&gt;&lt;LI&gt;no crypt.def is used.&lt;/LI&gt;&lt;LI&gt;Same firewalls with same policy in the same community but on R81.10.00/R77.20.81/R80.20.35 do not have this issue.&lt;/LI&gt;&lt;LI&gt;Behavior is seen in different environments.&lt;/LI&gt;&lt;LI&gt;use case is sftp backup !&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;A TAC case is created.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 14:27:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R81-20-05-SSH-traffic-is-excluded-from-VPN/m-p/194675#M9586</guid>
      <dc:creator>K_R_V</dc:creator>
      <dc:date>2023-10-10T14:27:37Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20.05+ - SSH traffic is excluded from VPN</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R81-20-05-SSH-traffic-is-excluded-from-VPN/m-p/194698#M9588</link>
      <description>&lt;P&gt;I also read release notes/known issues and only thing for ssh is protection related to threat prevention, and as far as sftp, dont see anything.&lt;/P&gt;
&lt;P&gt;Let us know what TAC says.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 17:22:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R81-20-05-SSH-traffic-is-excluded-from-VPN/m-p/194698#M9588</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-10T17:22:13Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20.05+ - SSH traffic is excluded from VPN</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R81-20-05-SSH-traffic-is-excluded-from-VPN/m-p/194790#M9596</link>
      <description>&lt;P&gt;"fw ctl set int accept_ssh_https_outgoing_clear 0" or&amp;nbsp;clish -c "kernel-parameter set name accept_ssh_https_outgoing_clear type int value 0" solves the issue.&lt;/P&gt;&lt;P&gt;This kernel parameter seems to be introduced in R81.10.05, according to TAC an SK is submitted for approval but not yet published .&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 11:47:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R81-20-05-SSH-traffic-is-excluded-from-VPN/m-p/194790#M9596</guid>
      <dc:creator>K_R_V</dc:creator>
      <dc:date>2023-10-11T11:47:57Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20.05+ - SSH traffic is excluded from VPN</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R81-20-05-SSH-traffic-is-excluded-from-VPN/m-p/194791#M9597</link>
      <description>&lt;P&gt;Thanks for letting us know.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 11:59:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R81-20-05-SSH-traffic-is-excluded-from-VPN/m-p/194791#M9597</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-11T11:59:30Z</dc:date>
    </item>
  </channel>
</rss>

