- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi,
just stumbled over this statement in https://support.checkpoint.com/results/sk/sk183394 :
Installation of any Jumbo Hotfix Accumulator Take or upgrade to a higher version will restore the default Gaia OS configuration (will implicitly enable the parameter "AllowAgentForwarding" again).
Therefore, you must perform this procedure again.
Since this a requires a lot of effort if you have a huge CP install base.
Will this somehow make it into a clish config parameter and survives upgrades?
Thanks
Regards
Looks like we plan to release a fix integrated into the jumbo for this: PMTR-117744
It isn’t in the jumbo hotfix yet.
Excellent point there @S_E_
I just checked my cluster and single gw lab and all of them show below. Cluster is R81.20 and cp-gw is R82 (all latest jumbo)
Andy
[Expert@CP-GW:0]# sshd -T -C addr=localhost | grep -i "AllowAgentForwarding"
allowagentforwarding yes
[Expert@CP-GW:0]#
While providing clish for said parameter is an RFE, I’m curious why we don’t fix the default sshd_config here, which seems simple enough.
Let me ask.
Looks like we plan to release a fix integrated into the jumbo for this: PMTR-117744
It isn’t in the jumbo hotfix yet.
Yep. My company's vulnerability management team has been flagging this issue and wasting a lot of time having us "fix" it one cluster at a time only for it to be undone in our next round of jumbos. We pushed for CFG to put it in a jumbo directly.
I still can't believe how much time we wasted on CVE-2023-48795 ("Terrapin"), which isn't even a vulnerability in the first place.
Good news!
Sounds good. Thanks.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY