- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi guys,
Can you help me with this please?
Trying to follow sk165685 but command does not work on r80.20.
Regards,
Checkpointer
I assume this does work in R80.40 / R81 only, as it reads: In R80.40, openSSL and openSSH were upgraded.
Then the command ssh -Q options are listed...
Thanks GW, is there any other way you might know of to get the information around supported MAC/HMACs in R80.20?
For SSH, the -Q option was added in OpenBSD 5.5 only. Try cat /etc/ssh/ssh_config to read config file 8)
See sk106031: How to change SSH encryption protocols and Message Authentication Code settings also.
Unfortunately, the underlying components require a newer version of the Linux kernel not present in R80.20.
Upgrade to at least R80.40, which is in wide use by our customers.
Up until R80.30 GAiA 3.10, Check Point includes OpenSSH 4.3p2, which corresponds to OpenBSD 3.9. Here is the version of the manpage you should use:
https://man.openbsd.org/OpenBSD-3.9/sshd_config
At that time, the only HMACs supported were hmac-md5 and hmac-sha1 (Turns out I was wrong about this. See below.). Of note, MD5 provides plenty of security for an HMAC.
With the move to a newer RHEL base, R80.30 management, R80.40 firewall, and up include OpenSSH 7.8p1, from mid-2018.
Hi Bob, thanks for this. What is the source of this information? Can I validate it with any SK's?
Version is obtained using 'sshd -v'. You can then check the OpenBSD 3.9 release notes, which say it includes OpenSSH 4.3. The manpage above is the OpenBSD 3.9 version of the manpage, though I somehow got the link text wrong. That link goes to sshd_config, which is the correct page. Look for the "MACs" option.
I also misinterpreted something I read elsewhere. OpenSSH 4.3 supports four HMACs: hmac-md5, hmac-sha1, hmac-ripemd160, hmac-sha1-96, hmac-md5-96.
Fantastic, thanks Bob.
I was able to get version with 'rpm -qa | grep ssh', 'sshd -v' didn't work in my (lab) r80.10.
Once again thank you so much for this, I am much obliged to you for answering my question!
Regards,
Checkpointer
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 21 | |
| 20 | |
| 16 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY