- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi Mates,
tried to allow ssh access to bitbucket.org via the official provided Application-Object "Bitbucket".
This object includes Port 80,433,22 etc.
For https traffic the rule matches but not for ssh traffic.
SSL-Inspection is not active.
Gateway Version R81.10 T130.
Workaround is to allow ssh to the Bitbucket IP-Ranges.
Someone else with this issue?
Cheers,
David
Application/Site objects can only match HTTP-like traffic. SSH doesn't quite use TLS (it uses most of the same primitives, but the negotiation is very unlike a TLS Client Hello), so enabling SSL Inspection almost certainly won't help.
You could use an FQDN object. These cause the firewall to look up the name in the object in the background and cache the IPs returned in a table which is then consulted when trying to match the object. For this to work reliably, clients must use the same DNS resolution path as the firewall.
According to this, SSH should be one of the supported ports for Bitbucket:
Not sure how it is detecting the use of Bitbucket over SSH, though...
Yup, just checked R81.20, shows the same.
Andy
So who can tell us❓
Did you ever open TAC case to get an official answer?
Andy
Either this built-in service is incorrect (SSH isn't supported) or the behavior is not correct.
Either way, the TAC should be involved: https://help.checkpoint.com
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 20 | |
| 19 | |
| 18 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY