Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Chris_Newman
Participant
Jump to solution

Is there a way to limit concurrent SSH sessions to a security gateway or management server to 5 or less?

I'm going through a PCI hardening document and they recommend "only five concurrent SSH sessions when connecting to the system".

0 Kudos
1 Solution

Accepted Solutions
Vladimir
Champion
Champion

I remember encountering same issue and dealing with it by means of QoS:

1. Enable QoS on the gateway

2. Create a rule on top of default QoS rule

3. Specify ssh as service and define destinations as your gateways or management servers BEHIND gateways

4. Right-click "Action" field of the rule and click "Edit Settings"

5. Click "Advanced"

6. Change setting as per this screenshot:

QoS-Advanced

7. Add tracking options to the rule and apply the policy:

QoS-ssh-policy

Cheers,

Vladimir

View solution in original post

1 Reply
Vladimir
Champion
Champion

I remember encountering same issue and dealing with it by means of QoS:

1. Enable QoS on the gateway

2. Create a rule on top of default QoS rule

3. Specify ssh as service and define destinations as your gateways or management servers BEHIND gateways

4. Right-click "Action" field of the rule and click "Edit Settings"

5. Click "Advanced"

6. Change setting as per this screenshot:

QoS-Advanced

7. Add tracking options to the rule and apply the policy:

QoS-ssh-policy

Cheers,

Vladimir

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events