Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Wolfgang
Authority
Authority

change ssh port on R80.40 and higher

 CheckMates,

changing the ssh port via /etc/ssh/sshd_config is broken since R80.40. You can change the port, restart sshd service everything will be fine. But after a reboot the changed entry is removed from sshd_config.

Is there a new clish command available for changing the ssh port or do we have to made the sshd_config readonly after the change ?

Wolfgang

6 Replies
Zolo
Contributor
Contributor

Starting from R80.40 Jumbo Hotfix Take 83, instead of editing/backing up /etc/ssh/sshd_config, you should edit/backup /etc/ssh/templates/sshd_config.templ and run /bin/sshd_template_xlate < /config/active

https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...

dede79
Contributor

SK was deleted and did not survive jumbo install i.e. on R81.10.

Is there actually a workig process to change ssh port permanently?

Arskazv
Participant

I also miss a permanent solution for this... In some cases, one may lose connection...

PhoneBoy
Admin
Admin

Checking the R82 EA, it appears the situation is the same (you need to edit the template file and it may not survive a JHF/upgrade).

Duane_Toler
Advisor

Do what @PhoneBoy says.  You need to write your changes to the template and they will be preserved/re-generated at each startup.  I've made a few custom changes myself this way and it works.

--
Ansible for Check Point APIs series: https://www.youtube.com/@EdgeCaseScenario and Substack
Arskazv
Participant

Yes, I have been using that,  but that template is overwritten by jumbo hotfixes. So it's not permanent in that way 😉

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events