- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Hi SMB Masters!
I would like to ask you if anyone have an experience how to setup SSH connection with keypair to Sparks. Anyone? I know it must be in bashUser etc. But SMB has no classic home folder for admin user for example. Where we should put keys if we want to do it?
For Security Gateway 80 / 600 / 700 / 1100 / 1200R/ 1400 appliances see here: https://community.checkpoint.com/t5/SMB-Gateways-Spark/Perform-scheduled-scripted-tasks-on-SMB-devic... and sk106836: How to configure SSH authentication using RSA key files on Security Gateway 80 / 600 / 700....
It's in the product documentation now: https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Centrally_Managed/EN/Content/Topics/SS...
Root's "home" directory is / (i.e. the root filesystem).
Which would imply that you can create a /.ssh/authorized_keys file.
However, in R81.10.05, it appears this is disabled in /pfrm2.0/etc/sshd_config
(Earlier code revisions use dropbear, which may already allow this)
You might be able to tweak the configuration to make this work.
The official procedure for this: https://support.checkpoint.com/results/sk/sk179986
Note that it only applies to Quantum Spark SMB appliances running R81.10.xx where OpenSSH is used instead of Dropbear.
Deleted.
It was still online last week. It's really annoying that published SKs constantly get retracted without any kind of explanation/justification.
Edit :
It seems like this SK's content made its way to the Admin Guide.
https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/SSH-...
That's probably where I read about this last week.
Deleted SKs are still an issue though.
Sk has been deleted.
It's in the product documentation now: https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Centrally_Managed/EN/Content/Topics/SS...
For Security Gateway 80 / 600 / 700 / 1100 / 1200R/ 1400 appliances see here: https://community.checkpoint.com/t5/SMB-Gateways-Spark/Perform-scheduled-scripted-tasks-on-SMB-devic... and sk106836: How to configure SSH authentication using RSA key files on Security Gateway 80 / 600 / 700....
@G_W_Albrecht and @PhoneBoy thank you guys! I am surprised that I was not able to find newest SK myself when I was digging in knowledge base.
mkdir /storage/.ssh
chmod 700 /storage/.ssh
cd /storage/.ssh
touch authorized_keys
chmod 600 authorized_keys
cat >> authorized_keys (paste your key(s), end with Ctrl-D)
sed -i '/^AuthorizedKeysFile/s!none!/storage/.ssh/authorized_keys!' /pfrm2.0/etc/sshd_config
/pfrm2.0/bin/sshd.sh
The last 2 commands need to be repeated after each firmware upgrade.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY