<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ports 18265, 18190, 19009 are exposed via Internet in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ports-18265-18190-19009-are-exposed-via-Internet/m-p/112922#M15725</link>
    <description>&lt;P&gt;18190 and 19009 are for SmartConsole, and 18265 is the ICA Tool.&lt;BR /&gt;Which suggests this gateway is also a management station (i.e. you've installed it standalone).&lt;BR /&gt;That might be...expected behavior.&lt;/P&gt;
&lt;P&gt;You can disable ICA tool via:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk39915" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk39915&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;Access to the other two ports should be controlled by GUI clients setting in cpconfig.&lt;/P&gt;</description>
    <pubDate>Wed, 10 Mar 2021 02:41:08 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-03-10T02:41:08Z</dc:date>
    <item>
      <title>Ports 18265, 18190, 19009 are exposed via Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ports-18265-18190-19009-are-exposed-via-Internet/m-p/112918#M15723</link>
      <description>&lt;P&gt;Hello team,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After a deploy with a new device, we see our WAN interfaz is reachable through these ports:&amp;nbsp;18265, 18190, 19009&lt;/P&gt;&lt;P&gt;Our device is SG 6200 Gaia R80.30.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In other devices as SG 2200 R77.30 and SG 5100 R80.10 their IP's are not reachable through those ports.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I understand this is normal but only internal communication, not exposed to internet due ICA services, but I'm affiard it could be a vulnerability.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Mar 2021 00:10:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ports-18265-18190-19009-are-exposed-via-Internet/m-p/112918#M15723</guid>
      <dc:creator>Almal_Luna</dc:creator>
      <dc:date>2021-03-10T00:10:32Z</dc:date>
    </item>
    <item>
      <title>Re: Ports 18265, 18190, 19009 are exposed via Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ports-18265-18190-19009-are-exposed-via-Internet/m-p/112922#M15725</link>
      <description>&lt;P&gt;18190 and 19009 are for SmartConsole, and 18265 is the ICA Tool.&lt;BR /&gt;Which suggests this gateway is also a management station (i.e. you've installed it standalone).&lt;BR /&gt;That might be...expected behavior.&lt;/P&gt;
&lt;P&gt;You can disable ICA tool via:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk39915" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk39915&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;Access to the other two ports should be controlled by GUI clients setting in cpconfig.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Mar 2021 02:41:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ports-18265-18190-19009-are-exposed-via-Internet/m-p/112922#M15725</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-10T02:41:08Z</dc:date>
    </item>
  </channel>
</rss>

