- Products
- Learn
- Local User Groups
- Partners
- More
Access Control and Threat Prevention Best Practices
5 November @ 5pm CET / 11am ET
Ask Check Point Threat Intelligence Anything!
October 28th, 9am ET / 3pm CET
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
Spark Management Portal and More!
Hello friends!
I am currently looking into implemnting ssh inspection feature for the checkpoint security gateway, and I was unable to find a lot of information or guides on this feature (except the two minimal guides on the checkpoint site) so I would be glad if someone can point me to a more comprehensive guide or document, or maybe answer some of my questions regarding this feature - the ssh client needs to ssh to the security gateway or to the ssh server (and the session just passes the security gateway)?
Thanks in advance:)
The only resource for SSH Deep Packet Inspection is the one @the_rock provided in the formal documentation. Most people aren't even aware this feature exists since it can't be configured in the SmartConsole GUI. You may also see references to "RDP Inspection" if you look around in the documentation hard enough; this feature had a very short lifespan and is no longer present.
Thank you very much for the replies!
What do you mean by "no longer present"?
Maybe you can confirm with TAC if they have any other additional info about it.
Andy
Hello @Timothy_Hall, did you mean that ssh inspection is a feature that is no longer present or rdp inspection?
Hi @Timothy_Hall, The ssh inspection feature had a very short lifespan and is no longer present or the rdp inspection?
RDP Inspection is no longer present. See here: Remote Desktop Inspection Still Supported?
ssh inspection is still supported, but rdp inspection is not, as per link Tim sent.
Andy
Once ssh inspection is turned on (ion), does that mean all current ssh traffic going thru the gw will break until you add all the public and private keys to the gw? With 'https inspection', you can bypass traffic you don't want inspected.
If I'm understanding the documentation correctly, we are only inspecting SSH connections where the public (and private) key is added to the gateway.
However, I haven't tested this.
You need to add the private key to the gateway? The documentation says you only need to add the public key
You can add the private key to improve the user experience, but it's not a requirement.
I understand. I followed the guide for configuring the ssh inspection but where can I actually see that the ssh traffic to the ssh server that it's key I added to the gateway is being inspected?
What does cpssh_config istatus tell you?
Man, learn something new from you all the time, I never knew of that command before 🙂
Andy
SSH Inspection is enabled
Well, that's a start.
The best way to confirm is via telnet to port 22 to the protected server.
This (along with troubleshooting) is listed at the bottom of the documentation linked earlier in this thread.
Yes, I tried it but I did not get the result shown in the documentation. Am I supposed to be able to see the ssh traffic inspected in the logs on the management server?
If it's not showing the Check Point specific SSH banner, then it's not doing inspection.
Recommend engaging with TAC for further assistance: https://help.checkpoint.com
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
25 | |
13 | |
9 | |
9 | |
7 | |
7 | |
7 | |
6 | |
4 | |
4 |
Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesWed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY