R80.x Ports Used for Communication by Various Check Point Modules

Document created by Heiko Ankenbrand Champion on Mar 1, 2018Last modified by Heiko Ankenbrand Champion on Dec 3, 2018
Version 79Show Document
  • View in full screen mode
Introduction

 

This drawing should give you an overview of the used R80 and R77 ports respectively communication flows. It should give you an overview of how different Check Point modules communicate with each other. Furthermore, services that are used for firewall operation are also considered. These firewall services are also partially mapped as implied rules in the set on the firewall.

 

Chapter

 

Architecture:

R80.x Security Gateway Architecture (Logical Packet Flow)

R80.x Security Gateway Architecture (Content Inspection) 

R80.x Security Gateway Architecture (Acceleration Card Offloading) 

R80.x Ports Used for Communication by Various Check Point Modules 

Performance Tuning:

R80.x Performance Tuning Tip - AES-NI 

R80.x Performance Tuning Tip - SMT (Hyper Threading) 

R80.x Performance Tuning Tip - Multi Queue 

R80.x Performance Tuning Tip - Connection Table 

R80.x Performance Tuning Tip - fw monitor

R80.x Performance Tuning Tip - TCPDUMP vs. CPPCAP 

R80.x Performance Tuning Tip – DDoS „fw sam“ vs. „fwaccel dos“ 

 

Overview

 

 

       You can download the drawing below as PDF.

 

References

 

Support Center: Ports used by Check Point software 

 

Versions

 

 + v1.4a bug fix, update port 1701 udp L2TP 09.04.2018
 + v1.4b bug fix 15.04.2018
 + v1.4c CPUSE update 17.04.2018
 + v1.4d legend fixed 17.04.2018

 + v1.4e add SmartLog and SmartView on port 443 20.04.2018

+ v1.4f bug fix 21.05.2018

+ v1.4g bug fix 25.05.2018

+ v1.4h add Backup ports 21, 22, 69 UDP and ClusterXL full sync port 256  30.05.2018

+ v1.4i add port 259 udp VPN link probeing 12.06.2018

+ v1.4j bug fix 17.06.2018

+ v1.4k add  OSPF/BGP route Sync 25.06.2018

+ v1.4l bug fix routed 29.06.2018

+ v1.4m bug fix tcp/udp ports 03.07.2018

+ v1.4n add port 256 13.07.2018

+ v1.4o bug fix / add TE ports 27.11.2018

 

old version 1.3:

+ v1.3a new designe (blue, gray), bug fix, add netflow, new names 27.03.2018

+ v1.3b add routing ports, bug fix designe 28.03.2018

+ v1.3c bug fix, rename ports (old) 29.03.2018

+ v1.3d bug fix 30.03.2018

+ v1.3e fix issue L2TP UDP port 1701

 

old version 1.1:

+ v1.1a - added r80.xx ports 16.03.2018

+ v1.1b - bug in drawing fixed 17.03.2018
+ v1.1c - add RSA, TACACS, Radius 19.03.2018
+ v1.1d - add 900, 259 Client-auth - deleted od 4.0 ports 20.03.2018

+ v1.1e - add OPSEC -delete R55 ports 21.03.2018
+ v1.1f - bug fix 22.03.2018

+ v1.1g - bug fix - add mail smtp -add dhcp - add snmp 25.03.2018

 

311 people found this helpful

Attachments

Outcomes