<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Restrict Access to Gaia Web Interface When RAVPN is in use in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Restrict-Access-to-Gaia-Web-Interface-When-RAVPN-is-in-use/m-p/276727#M105298</link>
    <description>&lt;P&gt;GAIA web portal cannot run on the same port if 443 is needed for visitor mode (RAVPN).&lt;/P&gt;
&lt;P&gt;You need to change the GAIA portal port to something different. You have to do this via clish or web interface and after that also change the platform portal in SmartConsole under the firewall object.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 695px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34222i2C044B20B40A5AD1/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34223iCC1FB965F3BC0C34/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Example clish config:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;cp-mgmt&amp;gt;&amp;nbsp;set&amp;nbsp;web&amp;nbsp;ssl-port&amp;nbsp;4434&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 08 May 2026 20:48:35 GMT</pubDate>
    <dc:creator>Lesley</dc:creator>
    <dc:date>2026-05-08T20:48:35Z</dc:date>
    <item>
      <title>Restrict Access to Gaia Web Interface When RAVPN is in use</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Restrict-Access-to-Gaia-Web-Interface-When-RAVPN-is-in-use/m-p/276719#M105294</link>
      <description>&lt;P&gt;Hey everyone. I see that the question of restricting access to the Gaia web interface from public IP's has been asked and answered many times, but what happens when Remote Access VPN is in use on the appliance, and port 443 needs to be publicly available in order to facilitate the VPN connection? Is the easiest way to change the Gaia web interface port to use something custom, and not related to the VPN negotiation at all, and then make sure that port is blocked in the rulebase for anything except admin machines?&lt;/P&gt;&lt;P&gt;This recently appeared in a pentest, and was flagged as a high priority issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 May 2026 18:45:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Restrict-Access-to-Gaia-Web-Interface-When-RAVPN-is-in-use/m-p/276719#M105294</guid>
      <dc:creator>cdooer</dc:creator>
      <dc:date>2026-05-08T18:45:58Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict Access to Gaia Web Interface When RAVPN is in use</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Restrict-Access-to-Gaia-Web-Interface-When-RAVPN-is-in-use/m-p/276727#M105298</link>
      <description>&lt;P&gt;GAIA web portal cannot run on the same port if 443 is needed for visitor mode (RAVPN).&lt;/P&gt;
&lt;P&gt;You need to change the GAIA portal port to something different. You have to do this via clish or web interface and after that also change the platform portal in SmartConsole under the firewall object.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 695px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34222i2C044B20B40A5AD1/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34223iCC1FB965F3BC0C34/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Example clish config:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;cp-mgmt&amp;gt;&amp;nbsp;set&amp;nbsp;web&amp;nbsp;ssl-port&amp;nbsp;4434&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 May 2026 20:48:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Restrict-Access-to-Gaia-Web-Interface-When-RAVPN-is-in-use/m-p/276727#M105298</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2026-05-08T20:48:35Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict Access to Gaia Web Interface When RAVPN is in use</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Restrict-Access-to-Gaia-Web-Interface-When-RAVPN-is-in-use/m-p/276736#M105304</link>
      <description>&lt;P&gt;Yes, you can change the port via clish:&amp;nbsp;set web ssl-port xxxx&lt;BR /&gt;You can also use System Configuration &amp;gt; Host Access to restrict what IPs are allowed to connect (independent of the firewall policy).&lt;BR /&gt;Believe this also applies to SSH.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 May 2026 21:14:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Restrict-Access-to-Gaia-Web-Interface-When-RAVPN-is-in-use/m-p/276736#M105304</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-05-08T21:14:32Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict Access to Gaia Web Interface When RAVPN is in use</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Restrict-Access-to-Gaia-Web-Interface-When-RAVPN-is-in-use/m-p/276773#M105313</link>
      <description>&lt;P&gt;So we have Visitor Mode enabled, and as I understand it this is required for the initial connection during the site creation. Gaia is also on port 443, and there don't seem to be any issues. I do see this option in the gateway configuration though...could changing it to Through Internal Interfaces solve the issue?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2026-05-11 080242.jpg" style="width: 699px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34225i0F1C0CB9AB40708E/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2026-05-11 080242.jpg" alt="Screenshot 2026-05-11 080242.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2026 12:04:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Restrict-Access-to-Gaia-Web-Interface-When-RAVPN-is-in-use/m-p/276773#M105313</guid>
      <dc:creator>cdooer</dc:creator>
      <dc:date>2026-05-11T12:04:07Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict Access to Gaia Web Interface When RAVPN is in use</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Restrict-Access-to-Gaia-Web-Interface-When-RAVPN-is-in-use/m-p/276789#M105322</link>
      <description>&lt;P&gt;Thx, probably best to change the port regardless. Also, the thing about host access is that it still allows you to connect to the web interface, it just doesn't allow you to login. The audit team is saying that is not sufficient.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2026 14:50:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Restrict-Access-to-Gaia-Web-Interface-When-RAVPN-is-in-use/m-p/276789#M105322</guid>
      <dc:creator>cdooer</dc:creator>
      <dc:date>2026-05-11T14:50:56Z</dc:date>
    </item>
  </channel>
</rss>

