- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: SecureXL and SSH
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SecureXL and SSH
We migrated to a pair of 16Ks running VSX. When we created the new VS and launched it successfully, everything works fine but one issue, a user can't ssh to his server when SecureXL is enabled. When it's disabled (fwaccel off) it works and they can SSH. MTU is currently set to 1500.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey @mickkel2179,
You can bypass SecureXL for specific connections or ports by following SK104468
I know this doesn't address the underlying issue, but may act as a temporary workaround whilst you troubleshoot the problem.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey Aaron,
Thanks for the response, really appreciate it! The client has to many IPs to list in order to use this feature. Right now we have a ticket in with R&D .. let's see how that unravels.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I agree with @AaronCP , but as you said, if there are too many IP addresses, then see what R&D says.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Which version & JHF is used?
If disabling secureXL resolves a symptom it's typically a bug and needs to be investigated with TAC.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey Chris,
The client is on 81.10 335 build and JHF Take 66
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can disable SecureXL (or more accurately prevent templating) for a specific service.
See: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
Specifically, you'll add the SSH port (22) to the tcp_f2f_ports table.
However, as stated by others on this thread, if disabling SecureXL "solves" a problem, it's likely a bug and the TAC should be engaged.
