- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello friends!
I am currently looking into implemnting ssh inspection feature for the checkpoint security gateway, and I was unable to find a lot of information or guides on this feature (except the two minimal guides on the checkpoint site) so I would be glad if someone can point me to a more comprehensive guide or document, or maybe answer some of my questions regarding this feature - the ssh client needs to ssh to the security gateway or to the ssh server (and the session just passes the security gateway)?
Thanks in advance:)
The only resource for SSH Deep Packet Inspection is the one @the_rock provided in the formal documentation. Most people aren't even aware this feature exists since it can't be configured in the SmartConsole GUI. You may also see references to "RDP Inspection" if you look around in the documentation hard enough; this feature had a very short lifespan and is no longer present.
Thank you very much for the replies!
What do you mean by "no longer present"?
Maybe you can confirm with TAC if they have any other additional info about it.
Andy
Hello @Timothy_Hall, did you mean that ssh inspection is a feature that is no longer present or rdp inspection?
Hi @Timothy_Hall, The ssh inspection feature had a very short lifespan and is no longer present or the rdp inspection?
RDP Inspection is no longer present. See here: Remote Desktop Inspection Still Supported?
ssh inspection is still supported, but rdp inspection is not, as per link Tim sent.
Andy
Once ssh inspection is turned on (ion), does that mean all current ssh traffic going thru the gw will break until you add all the public and private keys to the gw? With 'https inspection', you can bypass traffic you don't want inspected.
If I'm understanding the documentation correctly, we are only inspecting SSH connections where the public (and private) key is added to the gateway.
However, I haven't tested this.
You need to add the private key to the gateway? The documentation says you only need to add the public key
You can add the private key to improve the user experience, but it's not a requirement.
I understand. I followed the guide for configuring the ssh inspection but where can I actually see that the ssh traffic to the ssh server that it's key I added to the gateway is being inspected?
What does cpssh_config istatus tell you?
Man, learn something new from you all the time, I never knew of that command before 🙂
Andy
SSH Inspection is enabled
Well, that's a start.
The best way to confirm is via telnet to port 22 to the protected server.
This (along with troubleshooting) is listed at the bottom of the documentation linked earlier in this thread.
Yes, I tried it but I did not get the result shown in the documentation. Am I supposed to be able to see the ssh traffic inspected in the logs on the management server?
If it's not showing the Check Point specific SSH banner, then it's not doing inspection.
Recommend engaging with TAC for further assistance: https://help.checkpoint.com
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 27 | |
| 23 | |
| 15 | |
| 14 | |
| 12 | |
| 10 | |
| 6 | |
| 6 | |
| 5 | |
| 4 |
Wed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY