SSH policy matching
SSH policy check is disabled by default, and can be enabled in transparent and explicit-web policies. When it is enabled, SSH policy matching will only match the SSH policy.
The SSH Policy Redirect (ssh-policy-redirect
) command is no longer available.
To configure SSH policy check in the CLI:
config firewall policy edit <policy> set ssh-policy-check {disable | enable} next end
To configure SSH policy check in the CLI:
-
Go to Policy & Objects > Policy.
-
Edit a transparent or explicit policy, or create a new policy and set Type to Transparent or Explicit.
-
Enable or disable Enable SSH policy check.
-
Click OK.