Fortinet black logo

Administration Guide

SSH policy matching

SSH policy matching

SSH policy check is disabled by default, and can be enabled in transparent and explicit-web policies. When it is enabled, SSH policy matching will only match the SSH policy.

The SSH Policy Redirect (ssh-policy-redirect) command is no longer available.

To configure SSH policy check in the CLI:
config firewall policy
    edit <policy>
        set ssh-policy-check {disable | enable}
    next
end
To configure SSH policy check in the CLI:
  1. Go to Policy & Objects > Policy.

  2. Edit a transparent or explicit policy, or create a new policy and set Type to Transparent or Explicit.

  3. Enable or disable Enable SSH policy check.

  4. Click OK.

SSH policy matching

SSH policy check is disabled by default, and can be enabled in transparent and explicit-web policies. When it is enabled, SSH policy matching will only match the SSH policy.

The SSH Policy Redirect (ssh-policy-redirect) command is no longer available.

To configure SSH policy check in the CLI:
config firewall policy
    edit <policy>
        set ssh-policy-check {disable | enable}
    next
end
To configure SSH policy check in the CLI:
  1. Go to Policy & Objects > Policy.

  2. Edit a transparent or explicit policy, or create a new policy and set Type to Transparent or Explicit.

  3. Enable or disable Enable SSH policy check.

  4. Click OK.