- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Allow SSH to Application "bitbucket"
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Allow SSH to Application "bitbucket"
Hi Mates,
tried to allow ssh access to bitbucket.org via the official provided Application-Object "Bitbucket".
This object includes Port 80,433,22 etc.
For https traffic the rule matches but not for ssh traffic.
SSL-Inspection is not active.
Gateway Version R81.10 T130.
Workaround is to allow ssh to the Bitbucket IP-Ranges.
Someone else with this issue?
Cheers,
David
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Application/Site objects can only match HTTP-like traffic. SSH doesn't quite use TLS (it uses most of the same primitives, but the negotiation is very unlike a TLS Client Hello), so enabling SSL Inspection almost certainly won't help.
You could use an FQDN object. These cause the firewall to look up the name in the object in the background and cache the IPs returned in a table which is then consulted when trying to match the object. For this to work reliably, clients must use the same DNS resolution path as the firewall.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
According to this, SSH should be one of the supported ports for Bitbucket:
Not sure how it is detecting the use of Bitbucket over SSH, though...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yup, just checked R81.20, shows the same.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
So who can tell us❓
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Did you ever open TAC case to get an official answer?
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Either this built-in service is incorrect (SSH isn't supported) or the behavior is not correct.
Either way, the TAC should be involved: https://help.checkpoint.com