Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
SriNarasimha005
Contributor

SSH Deep Packet Inspection

Hello,

We're planning to implement SSH Deep Packet Inspection for the incoming traffic as mentioned here.


https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_ThreatPrevention_AdminGuide/Topics...

We've multiple servers allowing SSH incoming traffic from the Internet to DMZ.
1. Can you pls let me know how to implement this for any test connection, instead of globally for all servers?
2. Just by identifying the SSH-tunnelling, does it going to automatically drop it or any rules required?

0 Kudos
2 Replies
G_W_Albrecht
Legend Legend
Legend

Your linked Admin Guide shows how to Add an inspected SSH server - repeat for multiple servers. Current rules should work as before, added SSH servers are are inspected.

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
ww1m6
Explorer

Hi! Did you manage to implement ssh inspection?

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events