<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: A question on SIC in Firewall &amp; Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-Security-Management/A-question-on-SIC/m-p/283040#M106962</link>
    <description>&lt;P&gt;I did find some traffic in our latest attempt to upgrade VSX. 18210 was used and was failing when blocked. I believe it is used for the virtual systems as it has a weird way to reinitialize and reconnect SIC outside of the VSX0 SIC process.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2026 22:54:00 GMT</pubDate>
    <dc:creator>spottex</dc:creator>
    <dc:date>2026-09-29T22:54:00Z</dc:date>
    <item>
      <title>A question on SIC</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/A-question-on-SIC/m-p/72356#M82092</link>
      <description>&lt;P&gt;Considering that SIC uses certificates can I confirm that there is no keep-alive mechanism involved in the protocol at all (in the sense of the manager sending any keep-alive packets to the gateway at a certain frequency)?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please note that this question is purely educational and that there is no issue that needs to be resolved.&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2020 17:10:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/A-question-on-SIC/m-p/72356#M82092</guid>
      <dc:creator>Nick_Doropoulos</dc:creator>
      <dc:date>2020-01-15T17:10:31Z</dc:date>
    </item>
    <item>
      <title>Re: A question on SIC</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/A-question-on-SIC/m-p/72369#M82093</link>
      <description>Over SIC it's simply management talking to gateways and pulling/pushing data.</description>
      <pubDate>Wed, 15 Jan 2020 20:39:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/A-question-on-SIC/m-p/72369#M82093</guid>
      <dc:creator>Martin_Valenta</dc:creator>
      <dc:date>2020-01-15T20:39:11Z</dc:date>
    </item>
    <item>
      <title>Re: A question on SIC</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/A-question-on-SIC/m-p/72372#M82094</link>
      <description>&lt;P&gt;keepalive for what?&lt;BR /&gt;this can help you if i get your question fine...&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_LoggingAndMonitoring_AdminGuide/html_frameset.htm?topic=documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_LoggingAndMonitoring_AdminGuide/204500&amp;amp;anchor=o160533" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_LoggingAndMonitoring_AdminGuide/html_frameset.htm?topic=documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_LoggingAndMonitoring_AdminGuide/204500&amp;amp;anchor=o160533&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2020 21:00:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/A-question-on-SIC/m-p/72372#M82094</guid>
      <dc:creator>FraP</dc:creator>
      <dc:date>2020-01-15T21:00:08Z</dc:date>
    </item>
    <item>
      <title>Re: A question on SIC</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/A-question-on-SIC/m-p/72379#M82095</link>
      <description>&lt;P&gt;Here a small picture for "Secure Internal Communication" between Security Management Server and Security Gateway.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_20200115-231913_Edge.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4000iD659C0426D6B6017/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot_20200115-231913_Edge.jpg" alt="Screenshot_20200115-231913_Edge.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;SIC is used for the following policy install,&amp;nbsp;get topology,...&lt;/P&gt;
&lt;P&gt;More read here:&amp;nbsp;&lt;A href="https://community.checkpoint.com/docs/DOC-2740-r80x-ports-used-for-communication-by-various-check-point-modules" target="_blank" rel="noopener"&gt;R80.x - Ports Used for Communication by Various Check Point Modules&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Check Point components communicate with each other using SIC. SIC is based on SSL with digital Certificates. When a Security Management Server is installed, a Certificate Authority (CA) is created. The CA issues Certificates for all components that need to communicate with one another.&lt;/P&gt;
&lt;P&gt;For example, a remote Security Gateway needs a Certificate from the Security Management Server before a Security Policy is installed, or before a license can be attached to the Security Gateway. Whenever any two entities in a site (Security Management Server, Security Gateway) need to communicate, the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;sic_policy.conf&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;file is referenced.&lt;/P&gt;
&lt;P&gt;Communication takes place over the Check Point communication layer. This channel is encrypted in various ways. This layer can be called the SIC layer. The SIC ports used are:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Port 18209, which is used for communication between the Security Gateway and the CA for status, to issue, and revoke.&lt;/LI&gt;
&lt;LI&gt;Port 18210, which is used to pull certificates from the CA.&lt;/LI&gt;
&lt;LI&gt;Port 18211, which is the port used by the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;cpd&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;daemon on the Security Gateway to receive the Certificate (by clicking "Initialize" in SmartDashboard).&lt;/LI&gt;
&lt;LI&gt;Port 18191, which is used for policy install,... ( More read here:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Policy-Management/R80-x-Policy-Installation-Flowchart/m-p/67458#M3971" target="_self"&gt;R80.x - Policy Installation Flowchart&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Port 18192,&amp;nbsp;which is used for get topology,...&lt;/LI&gt;
&lt;LI&gt;Other ports...&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;PS:&lt;BR /&gt;&lt;SPAN style="font-family: inherit;"&gt;There is no keep-alive mechanism involved.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2020 22:44:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/A-question-on-SIC/m-p/72379#M82095</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2020-01-15T22:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: A question on SIC</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/A-question-on-SIC/m-p/80867#M82096</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Could you please explain difference between the two steps 18210 and 18211&lt;/P&gt;&lt;P&gt;It seems 18211 is sufficient since this would allow to push certificates from ICA (SMS) to Security Gateway...&lt;/P&gt;&lt;P&gt;You said that port 18210 is used to pull certificate from CA, and I am just wondering why do we need this since security Gateway could receive certificates from SMS (port 18211)&lt;/P&gt;&lt;P&gt;what am I missing??&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Sun, 05 Apr 2020 12:33:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/A-question-on-SIC/m-p/80867#M82096</guid>
      <dc:creator>Uchiha_Itachi</dc:creator>
      <dc:date>2020-04-05T12:33:53Z</dc:date>
    </item>
    <item>
      <title>Re: A question on SIC</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/A-question-on-SIC/m-p/281515#M106618</link>
      <description>&lt;P&gt;This is the question I have right now and looking for actual evidence specifying it.&amp;nbsp; You push it from the manager, If that has an issue try and pull it down from the firewall.&lt;BR /&gt;&lt;BR /&gt;But is there a need for the gateway to respond to a push with a pull to complete an initial SIC comms?&lt;/P&gt;&lt;P&gt;Looking for documentation and not&amp;nbsp;sk97833. As that is just CP talk to cover them which is enable it anyway.&lt;/P&gt;&lt;P&gt;Our configuration has another FW between the gateway and the Manager which does not allow&amp;nbsp;&lt;SPAN&gt;18210 traffic. SIC did not complete and we had to roll back to previous snapshots before we realised this is the possible fix.&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A few say yes it is needed, But looking for evidence that states it. Our VSX update to a new major version is 2 month approval and a 8 hour process so really want to have it acknowledged because if we do the change again and it fails we are out another month or two.&lt;/P&gt;&lt;P&gt;Update but not conclusive. I'm still keen to find the evidence:&lt;BR /&gt;I just read a CM post where a new SIC request was failing, but once&amp;nbsp;&lt;SPAN&gt;18210 was allowed their SIC issue was fixed.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2026 00:49:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/A-question-on-SIC/m-p/281515#M106618</guid>
      <dc:creator>spottex</dc:creator>
      <dc:date>2026-08-26T00:49:11Z</dc:date>
    </item>
    <item>
      <title>Re: A question on SIC</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/A-question-on-SIC/m-p/281551#M106631</link>
      <description>&lt;P&gt;When you establish SIC with non-Check Point devices (e.g, OPSEC clients), it requires a connection to TCP 18210:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk93538" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk93538&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;The "pull" in this case is for the certificate issued by the ICA, which is generated as part of the SIC process.&lt;BR /&gt;That's why we list this as a requirement in sk97833.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2026 20:01:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/A-question-on-SIC/m-p/281551#M106631</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-08-26T20:01:00Z</dc:date>
    </item>
    <item>
      <title>Re: A question on SIC</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/A-question-on-SIC/m-p/283040#M106962</link>
      <description>&lt;P&gt;I did find some traffic in our latest attempt to upgrade VSX. 18210 was used and was failing when blocked. I believe it is used for the virtual systems as it has a weird way to reinitialize and reconnect SIC outside of the VSX0 SIC process.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2026 22:54:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/A-question-on-SIC/m-p/283040#M106962</guid>
      <dc:creator>spottex</dc:creator>
      <dc:date>2026-09-29T22:54:00Z</dc:date>
    </item>
  </channel>
</rss>

