- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
hello
I am new to checkpoint and I would like to know how can I check which SSH version is being configured in the checkpoint devices.
Currently I have VSX clusters running R75.40VS and R77.30.
Usually, if I want to check the SSH version I can change SSH protocol version in putty to 1 and try to login to the VSX device.
But if I want to check which SSH version that is allowed in the VSX devices, How Can I do that?
Also, if I want to configure SSH Version 1 on the VSX device how can i do that?
Your Help would be much appreciated.
By default, only SSHv2 is supported in all versions of Gaia and SecurePlatform.
This is because SSHv1 is considered not secure.
If you don't mind me asking, what is your reason for needing to enable SSHv1?
Hi
Thanks for the response.
I am working on checkpoint now and I am new to it.
I know in cisco we can check and configure the ssh version in ASA firewall. I just wanted to know if checkpoint has similar feature or it supports only SSHv2 by default.
I would also like to ask another question, the service object for ssh(tcp port 22) in smartdashboard, does it allow only sshv2 or both sshv1 and sshv2.
Also, if that service object allows both sshv1 and sshv2, is there a way to configure that to allow only sshv2.
Thank in advance
Ravi
I believe it's possible to enable SSHv1 by editing /etc/ssh/sshd_config and restarting sshd.
I haven't tried it and don't necessarily recommend it.
The "ssh" service allows SSHv1 and SSHv2.
If you want to enforce the use of SSHv2, there is a separate service called ssh_version_2 that only allows SSHv2.
Thanks for your response.
This sshv2 service, is it predefined or we have to define it when we are creating our policy?
If we were to define it, how can I do that?
Thanks
Ravi
It’s predefined
Hi
When I open the cat /etc/ssh/sshd_config file, I see the below result.
# $OpenBSD: sshd_config,v 1.73 2005/12/06 22:38:28 reyk Exp $
# This is the sshd server system-wide configuration file. See
# sshd_config(5) for more information.
# This sshd was compiled with PATH=/usr/local/bin:/bin:/usr/bin
# The strategy used for options in the default sshd_config shipped with
# OpenSSH is to specify options with their default value where
# possible, but leave them commented. Uncommented options change a
# default value.
#Port 22
#Protocol 2,1
Protocol 2 ----> Does this mean we are using only SSH v2 not SSH v1
#AddressFamily any
#ListenAddress 0.0.0.0
#ListenAddress ::
# HostKey for protocol version 1
#HostKey /etc/ssh/ssh_host_key
# HostKeys for protocol version 2
HostKey /etc/ssh/ssh_host_rsa_key
HostKey /etc/ssh/ssh_host_dsa_key
Does Protocol 2 meas SSH v2?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 16 | |
| 7 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY