SSH Proxy decryption disables vulnerability protection?

Showing results for 
Search instead for 
Did you mean: 

SSH Proxy decryption disables vulnerability protection?

L3 Networker

Hello everyone,


  I'm doing some tests with decryption and vulnerability protection. I configured NAT and security policies to permit ssh access to an internal ssh server from the outside and I attached a vulnerability protection profile to the policy. In the vulnerability protection profile I set an exception to block bruteforce login attacks after 2 failed attempts:




This configuration works fine and connections are reset after 2 failed login. Anyway, if I add a SSH decryption policy (SSH proxy) to this connection, the bruteforce login signature is no more triggered by the failed login attempts, so it is no more effective.


Is this an issue or is it "by design", due to the fact that the firewall acts as a man in the middle for the ssh connections?


L7 Applicator

That's an interesting find. Please open a case with Support.

I opened a case with the support and they confirmed this issue. Waiting for their research and feedback.



The engineering team confirmed that this is an expected behavior. This is their explanation:


In case SSH-proxy is enabled, the signature 31914 will act on decrypted traffic. Hence, this sig will not trigger because it can not detect the pattern of the failed authentication in the decrypted traffic.


Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!