Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
antsvett3
Participant
Jump to solution

One interface active cause ssh/https connectivity?

Hi All,

I'm trying to set up a lab but I only have my laptop connected to my check point appliance. When i have policy installed permitting my laptop to the firewall on ssh/https I can not connect. I'm wondering if this is because I only have the Mgmt interface up. When looking at the logs the connection is bypassing the accept and going to the clean up rule. Unload the policy and no issues. I'm Running R81.10 jumbo take 181.

Any insight is appreciated.

 

Thanks,

Anthony

0 Kudos
1 Solution

Accepted Solutions
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

The IP has a typo 182 rather than 192.

CCSM R77/R80/ELITE

View solution in original post

12 Replies
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

How have you defined the object / rules and what does the topology of the gateway object otherwise look like?

CCSM R77/R80/ELITE
0 Kudos
antsvett3
Participant

Hi,

I forgot to mention this is a standalone environment.

I've attached some screenshots. I don't see any issue.

 

 

 

0 Kudos
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

Kindly share the properties of the host object "H-192.168.1.2" ?

CCSM R77/R80/ELITE
0 Kudos
antsvett3
Participant

pls see attached

0 Kudos
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

The IP has a typo 182 rather than 192.

CCSM R77/R80/ELITE
the_rock
MVP Platinum
MVP Platinum

Good catch Chris, thats gotta be it.

Best,
Andy
0 Kudos
antsvett3
Participant

OMG you're right. I'm so sorry. I appreciate the eyes.

0 Kudos
the_rock
MVP Platinum
MVP Platinum

2 things could my eye. Shows failing on rule 3, but clean up rule is 3. Do you have another ordered layer because if yes, it needs to be allowed on it. Also, what does fw stat show?

See example from my lab:

Screenshot_3.png

Screenshot_1.png

Screenshot_2.png

   

Best,
Andy
0 Kudos
antsvett3
Participant

sorry, thats because i just deleted a rule after i tried to create an interface without having a connection to it. Prior to that it said dropped by rule 2.

 

[Expert@inet-fw:0]# fw stat
HOST POLICY DATE
localhost test-ssh 4Dec2025 10:38:42 : [>Mgmt] [<Mgmt]

0 Kudos
the_rock
MVP Platinum
MVP Platinum

What time zone are you in? If you want, we can do quick remote in a bit on my break and Im sure we can figure it out.

Best,
Andy
0 Kudos
antsvett3
Participant

Thanks Andy. Looks like I had a typo in the IP and its working now. Appreciate all the feedback.

0 Kudos
the_rock
MVP Platinum
MVP Platinum

It happens, no worries.

Best,
Andy
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events