<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How can I block ports from outside and allow it for internal communications? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-can-I-block-ports-from-outside-and-allow-it-for-internal/m-p/18541#M1395</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of our vulnerability scanner gave the following ports as vulnerable, so we want those ports to be blocked from outside and to be allowed from the inside for inside communications.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These are the ports&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt; 264/tcp - fw1_generic. &lt;BR data-jive-statusinputadd="true" data-jive-truncation-flag="true" /&gt;500/udp - ikev1. &lt;BR data-jive-statusinputadd="true" data-jive-truncation-flag="true" /&gt;18231/tcp&lt;/P&gt;&lt;P&gt;18264/tcp - cp_ica&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;how can i do this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 25 Apr 2018 12:19:52 GMT</pubDate>
    <dc:creator>Shehan_Wickrama</dc:creator>
    <dc:date>2018-04-25T12:19:52Z</dc:date>
    <item>
      <title>How can I block ports from outside and allow it for internal communications?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-can-I-block-ports-from-outside-and-allow-it-for-internal/m-p/18541#M1395</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of our vulnerability scanner gave the following ports as vulnerable, so we want those ports to be blocked from outside and to be allowed from the inside for inside communications.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These are the ports&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt; 264/tcp - fw1_generic. &lt;BR data-jive-statusinputadd="true" data-jive-truncation-flag="true" /&gt;500/udp - ikev1. &lt;BR data-jive-statusinputadd="true" data-jive-truncation-flag="true" /&gt;18231/tcp&lt;/P&gt;&lt;P&gt;18264/tcp - cp_ica&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;how can i do this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Apr 2018 12:19:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-can-I-block-ports-from-outside-and-allow-it-for-internal/m-p/18541#M1395</guid>
      <dc:creator>Shehan_Wickrama</dc:creator>
      <dc:date>2018-04-25T12:19:52Z</dc:date>
    </item>
    <item>
      <title>Re: How can I block ports from outside and allow it for internal communications?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-can-I-block-ports-from-outside-and-allow-it-for-internal/m-p/18542#M1396</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I feel like I might be missing something with your question, but I think there are&amp;nbsp;several&amp;nbsp;ways to achieve this...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SRC: Internal Networks Group&amp;nbsp;&lt;STRONG style="color: #ff0000;"&gt;[NEGATED]&lt;/STRONG&gt; | DST: Any | SVC: ports | ACT:&amp;nbsp;drop&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;--or--&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SRC: Internal Networks Group | DST: Any | SVC: ports | ACT: allow&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp;* I'd have several more specific rules of the above rule with explicit destinations...&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;SRC:&amp;nbsp;Any | DST: Any | SVC: ports | ACT:&amp;nbsp;drop&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;--or--&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Other combinations...&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Apr 2018 21:09:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-can-I-block-ports-from-outside-and-allow-it-for-internal/m-p/18542#M1396</guid>
      <dc:creator>Brian_Deutmeyer</dc:creator>
      <dc:date>2018-04-25T21:09:23Z</dc:date>
    </item>
    <item>
      <title>Re: How can I block ports from outside and allow it for internal communications?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-can-I-block-ports-from-outside-and-allow-it-for-internal/m-p/18543#M1397</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Some of these are covered by implied rules.&lt;/P&gt;&lt;P&gt;To confirm this, go to Global Properties, click the appropriate checkbox, and install policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64834_pastedImage_1.png" style="width: auto; height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will see log entries on Rule 0.&lt;/P&gt;&lt;P&gt;In which case you will have to work to disable the implied rules, but this is NOT recommended.&lt;/P&gt;&lt;P&gt;Refer to:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk43401&amp;amp;partition=General&amp;amp;product=Security" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk43401&amp;amp;partition=General&amp;amp;product=Security"&gt;How to completely disable FireWall Implied Rules&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Apr 2018 22:11:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-can-I-block-ports-from-outside-and-allow-it-for-internal/m-p/18543#M1397</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-04-25T22:11:08Z</dc:date>
    </item>
    <item>
      <title>Re: How can I block ports from outside and allow it for internal communications?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-can-I-block-ports-from-outside-and-allow-it-for-internal/m-p/18544#M1398</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Brian,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank You for the reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Shehan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 May 2018 04:57:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-can-I-block-ports-from-outside-and-allow-it-for-internal/m-p/18544#M1398</guid>
      <dc:creator>Shehan_Wickrama</dc:creator>
      <dc:date>2018-05-01T04:57:35Z</dc:date>
    </item>
    <item>
      <title>Re: How can I block ports from outside and allow it for internal communications?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-can-I-block-ports-from-outside-and-allow-it-for-internal/m-p/18545#M1399</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dameon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply. I have disabled some with the implied rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Shehan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 May 2018 04:58:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-can-I-block-ports-from-outside-and-allow-it-for-internal/m-p/18545#M1399</guid>
      <dc:creator>Shehan_Wickrama</dc:creator>
      <dc:date>2018-05-01T04:58:54Z</dc:date>
    </item>
    <item>
      <title>Re: How can I block ports from outside and allow it for internal communications?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-can-I-block-ports-from-outside-and-allow-it-for-internal/m-p/74072#M5700</link>
      <description>&lt;P&gt;G&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;reat answer PhoneBoy, how to do this for 600 and 1100? thc&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 04:43:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-can-I-block-ports-from-outside-and-allow-it-for-internal/m-p/74072#M5700</guid>
      <dc:creator>kreynolds</dc:creator>
      <dc:date>2020-02-04T04:43:45Z</dc:date>
    </item>
  </channel>
</rss>

