- Products
- Learn
- Local User Groups
- Partners
- More
Call For Papers
Your Expertise, Our Stage
Ink Dragon: A Major Nation-State Campaign
Watch HereAI Security Masters E5:
Powering Prevention: The AI Driving Check Point’s ThreatCloud
The Great Exposure Reset
AI Security Masters E4:
Introducing Cyata, Securing the Agentic AI Era
CheckMates Go:
CheckMates Fest
Hi,
I can't SSH to the firewall the I connect to via remote access VPN. Firewall rules are in place for SSH and webUI access to the firewall. I know in other VPN communities there is a tab for "excluded services". Is there a similar option for remote access VPN community?
I can get to the webUI but I can't SSH. Logs show traffic being decrypted.
I am running R81.10 mgmt and R80.40 firewall.
Thank you.
Thank you Rock and Genesis for your help. I found the issue. My SSH session was saved with the external IP, and I did not realize until now. 😅
Do you see any logs for port 22 when trying?
Yup
What do they show? Did you try zdebug on command line?
Hmm I don't see logs anymore but I did enable split tunneling and manually specified the encryption domain.
I do have a firewall rule that should allow this traffic...
Src: office mode network
Dst: FW
Services: SSH and webUI port
I am able to access the webUI and I see accept and decrypt logs for this traffic from my office mode IP to the internal IP of the firewall.
When I try to SSH I don't see logs. I do see drops in the zdebug. It shows this connection being dropped but the weird thing is the source is my external IP trying to hit destination of the external IP of the firewall.
Shouldn't this traffic be hitting the same rule that allows webUI access?
Message me directly, I have time to do remote, I have a feeling its something simple you might be missing.
Cheers!
Silly question have you updated the allowed list in GAIA?
Thank you Rock and Genesis for your help. I found the issue. My SSH session was saved with the external IP, and I did not realize until now. 😅
Well, sometimes smallest things pose a problem. Glad it works now : - )
Its a good reminder to us all, check the basics first!
I agree with you wholeheartedly!
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 35 | |
| 22 | |
| 21 | |
| 13 | |
| 9 | |
| 9 | |
| 8 | |
| 8 | |
| 8 | |
| 7 |
Tue 17 Mar 2026 @ 03:00 PM (CET)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - EMEATue 17 Mar 2026 @ 02:00 PM (EDT)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - AMERWed 18 Mar 2026 @ 10:00 AM (CET)
The Cloud Architects Series: An introduction to Check Point Hybrid Mesh in 2026 - In Seven LanguagesTue 24 Mar 2026 @ 04:00 PM (CET)
Maestro Masters EMEA: Hyperscale Firewall Architectures and OptimizationTue 17 Mar 2026 @ 03:00 PM (CET)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - EMEATue 17 Mar 2026 @ 02:00 PM (EDT)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - AMERWed 18 Mar 2026 @ 10:00 AM (CET)
The Cloud Architects Series: An introduction to Check Point Hybrid Mesh in 2026 - In Seven LanguagesTue 24 Mar 2026 @ 04:00 PM (CET)
Maestro Masters EMEA: Hyperscale Firewall Architectures and OptimizationTue 24 Mar 2026 @ 03:00 PM (EDT)
Maestro Masters Americas: Hyperscale Firewall Architectures and OptimizationTue 24 Mar 2026 @ 06:00 PM (COT)
San Pedro Sula: Spark Firewall y AI-Powered Security ManagementThu 26 Mar 2026 @ 06:00 PM (COT)
Tegucigalpa: Spark Firewall y AI-Powered Security ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY