CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDefense
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-01-17
Senior Member
 
Join Date: 2006-09-26
Posts: 804
Rep Power: 3
cciesec2006 has an average reputation (10+)
Default blocking SSH version 1 in smartdefense

I have NGx R65 with HFA_02 running on Nokia and being managed by a
CMA inside Provider-1.

I set SmartDefense default_protection to "monitor" and not blocking
ssh version 1; however, I still see this:

Number: 3014
Date: 17Jan2008
Time: 12:18:08
Interface: eth1c0
Origin: dca-Nokia-1-P
Type: Alert
Action: Reject
Service: gssh (22)
Source Port: 49978
Source: 192.168.15.10
Destination: h_192.168.2.3 (192.168.2.3)
Protocol: tcp
Information: message_info: SSH version 1.x is not allowed
Product: VPN-1 Power/UTM
SmartDefense Profile: Default_Protection
Policy Info: Policy Name: Nokia
Created at: Thu Jan 17 11:17:44 2008
Installed from: test_CMA


basically, it blocks ssh version 1 on my network even though I have it
to either "in-active" or "monitor only". It still blocks ssh version 1.

How do I go about fixing this? Thanks.
Reply With Quote
  #2 (permalink)  
Old 2008-01-19
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,660
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: blocking SSH version 1 in smartdefense

Do you have any rules that restrict a connection to SSHv2 only?
I saw this once where there was a rule to allow inbound SSHv2 and a rule to allow SSHv1 to the Internet router and the v1 was getting dropped. Changing the SSHv2 rule to SSH and life was good.

I never followed up on it so I don't know how to fix it.
Reply With Quote
  #3 (permalink)  
Old 2008-01-19
Senior Member
 
Join Date: 2006-09-26
Posts: 804
Rep Power: 3
cciesec2006 has an average reputation (10+)
Default Re: blocking SSH version 1 in smartdefense

Actually, in my ruleset, I have the following:

Source Destination Service Action
Any Any ssh-v2 Accept
ssh

both inbound and outbound ssh version 1 is blocked by SmartDefense
even though it is set to monitor
Reply With Quote
  #4 (permalink)  
Old 2008-06-06
Junior Member
 
Join Date: 2008-06-05
Posts: 1
Rep Power: 0
rklopoto has an average reputation (10+)
Default Re: blocking SSH version 1 in smartdefense

I dont know if you ever figured this out, but I had the same problem yesterday. I wanted to add to this message for future searchers.

If you look closely at the "ssh version 2" object, you'll notice that its description says "SSH2 protocol only, block SSH1". Even if you have ssh, in that group, this object will cause it to block. If you want ssh1 and ssh2, use the object "SSH".

Hope this helps and isn't too late.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 17:57.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0