- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
We followed the upgrade guide and after installing standby gw to R81,10, after reboot ssh was not possible any more.
Action plan:
In SmartConsole
, change the cluster object version to R81.10.
On the Cluster Member
M3:
Upgrade to R81.10
Note - If you perform a Clean Install
of R81.10, then you must establish SIC
in SmartConsole with this Cluster Member
Enable the MVC
Message was
[Expert@n.n.n.n]# ssh n.n.n.n
This system is for authorized use only.
admin@n.n.n.n: Permission denied (publickey).
Before upgrade login with user passwort was possible and we do not use key auth.
Only way to connect to 81,10 GW was via smart console, actions , "open shell" and enable MVC this way.
Is this expected behaviour?
The installation was done on a test system and for production we need to know if smart console is the only way to enable MVC or should ssh working.
Serial console is not available in this scenario.
Thanks for help in advance.
When you do a version upgrade, the system will not have a valid policy until a new one compiled against the target version is pushed from SmartConsole.
That will definitely break SSH (among other things).
Which Jumbo Take is installed ? Recommended Take is 95.
Installed was JHF192 or higher.
JHF 192 is mostly like version R80.40.
Cause R81.10 currently only in take 95.
This can happen if you're connecting through the firewall to some other interface on the standby member. Unless you're running VSX, Check Point firewalls put all interfaces into a single routing table, so they don't really have a "management interface". You should always SSH to the closest interface to you from a routing perspective.
When you do a version upgrade, the system will not have a valid policy until a new one compiled against the target version is pushed from SmartConsole.
That will definitely break SSH (among other things).
I dont ever recall losing ssh access when doing cluster upgrade (had done many of them), though I could be mistaken when I say this, but Im pretty positive that even with initial policy loaded, ssh still works, just defaultfilter would block it.
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 20 | |
| 20 | |
| 16 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY