<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Disconnect after disabling: Accept Remote Access Control Connections in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Disconnect-after-disabling-Accept-Remote-Access-Control/m-p/129578#M18975</link>
    <description>&lt;P&gt;From&amp;nbsp;sk52421 Ports used by Check Point software it does look like that:&lt;/P&gt;
&lt;TABLE id="filterportTable" border="1" width="100%" cellspacing="2" cellpadding="4"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;TCP&lt;/TD&gt;
&lt;TD&gt;264&lt;/TD&gt;
&lt;TD&gt;&lt;EM&gt;FW1_topo&lt;/EM&gt;&amp;nbsp;- Check Point Security Gateway SecuRemote Topology Requests&lt;/TD&gt;
&lt;TD&gt;Topology Download from Security Gateway (by FWD daemon) to SecuRemote (build 4100 and higher) and SecureClient&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But in&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk42815&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank" rel="noopener"&gt;sk42815: How to create a site to site (S2S) VPN without using &lt;STRONG&gt;control&lt;/STRONG&gt; &lt;STRONG&gt;connections&lt;/STRONG&gt;&lt;/A&gt;&amp;nbsp;we learn:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you turn off implied rules (if you disable them in &lt;/SPAN&gt;&lt;STRONG&gt;Global Properties &lt;/STRONG&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;STRONG&gt; Firewall&lt;/STRONG&gt;&lt;SPAN&gt; &amp;gt; &lt;/SPAN&gt;&lt;STRONG&gt;Accept VPN-1 power/UTM control connection&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;and &lt;/SPAN&gt;&lt;STRONG&gt;Accept Remote Access control connections&lt;/STRONG&gt;&lt;SPAN&gt;),&amp;nbsp;you may not be able to install a policy on a Remote VPN-1 Power Gateway. Even if you define explicit rules in place of the implied rules, you may still not be able to install the policy.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 16 Sep 2021 14:20:58 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2021-09-16T14:20:58Z</dc:date>
    <item>
      <title>VPN Disconnect after disabling: Accept Remote Access Control Connections</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Disconnect-after-disabling-Accept-Remote-Access-Control/m-p/129576#M18974</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;TCP 264 was opened on our gateways. As we don't use Remote Access VPN on our Gateway we would like to disable it.&lt;/P&gt;&lt;P&gt;We only have Site 2 Site VPN with Azure.(built in Azure VPN, not a Checkpoint VM in Azure)&lt;/P&gt;&lt;P&gt;After disabling "Accept Remote Access Control Connections" on our Checkpoint gateway, the VPN with Azure get disconnected.&lt;/P&gt;&lt;P&gt;Re-enabling it and Install Policiies makes the VPN up again&lt;/P&gt;&lt;P&gt;From my understanding TCP 264 is only relevant with for Remote Access VPN, not Site2Site...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does it make sense?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Sep 2021 13:36:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Disconnect-after-disabling-Accept-Remote-Access-Control/m-p/129576#M18974</guid>
      <dc:creator>DR_74</dc:creator>
      <dc:date>2021-09-16T13:36:27Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Disconnect after disabling: Accept Remote Access Control Connections</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Disconnect-after-disabling-Accept-Remote-Access-Control/m-p/129578#M18975</link>
      <description>&lt;P&gt;From&amp;nbsp;sk52421 Ports used by Check Point software it does look like that:&lt;/P&gt;
&lt;TABLE id="filterportTable" border="1" width="100%" cellspacing="2" cellpadding="4"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;TCP&lt;/TD&gt;
&lt;TD&gt;264&lt;/TD&gt;
&lt;TD&gt;&lt;EM&gt;FW1_topo&lt;/EM&gt;&amp;nbsp;- Check Point Security Gateway SecuRemote Topology Requests&lt;/TD&gt;
&lt;TD&gt;Topology Download from Security Gateway (by FWD daemon) to SecuRemote (build 4100 and higher) and SecureClient&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But in&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk42815&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank" rel="noopener"&gt;sk42815: How to create a site to site (S2S) VPN without using &lt;STRONG&gt;control&lt;/STRONG&gt; &lt;STRONG&gt;connections&lt;/STRONG&gt;&lt;/A&gt;&amp;nbsp;we learn:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you turn off implied rules (if you disable them in &lt;/SPAN&gt;&lt;STRONG&gt;Global Properties &lt;/STRONG&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;STRONG&gt; Firewall&lt;/STRONG&gt;&lt;SPAN&gt; &amp;gt; &lt;/SPAN&gt;&lt;STRONG&gt;Accept VPN-1 power/UTM control connection&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;and &lt;/SPAN&gt;&lt;STRONG&gt;Accept Remote Access control connections&lt;/STRONG&gt;&lt;SPAN&gt;),&amp;nbsp;you may not be able to install a policy on a Remote VPN-1 Power Gateway. Even if you define explicit rules in place of the implied rules, you may still not be able to install the policy.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Sep 2021 14:20:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Disconnect-after-disabling-Accept-Remote-Access-Control/m-p/129578#M18975</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-09-16T14:20:58Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Disconnect after disabling: Accept Remote Access Control Connections</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Disconnect-after-disabling-Accept-Remote-Access-Control/m-p/129580#M18976</link>
      <description>&lt;P&gt;Thanks, maybe I don't understand the sk but it does'nt make sense in our environment:&lt;/P&gt;&lt;P&gt;- We have an On-Prem gateway and the remote GW is an Azure gateway.&lt;/P&gt;&lt;P&gt;- We only disable : &lt;STRONG&gt;Accept Remote Access control connections&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;We don't use Remote VPN.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Sep 2021 14:29:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Disconnect-after-disabling-Accept-Remote-Access-Control/m-p/129580#M18976</guid>
      <dc:creator>DR_74</dc:creator>
      <dc:date>2021-09-16T14:29:31Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Disconnect after disabling: Accept Remote Access Control Connections</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Disconnect-after-disabling-Accept-Remote-Access-Control/m-p/129583#M18977</link>
      <description>&lt;P&gt;I suspect that option is doing something else in addition.&lt;BR /&gt;Recommend the following:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk132712&amp;amp;partition=Advanced&amp;amp;product=Mobile" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk132712&amp;amp;partition=Advanced&amp;amp;product=Mobile&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Sep 2021 14:38:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Disconnect-after-disabling-Accept-Remote-Access-Control/m-p/129583#M18977</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-09-16T14:38:20Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Disconnect after disabling: Accept Remote Access Control Connections</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Disconnect-after-disabling-Accept-Remote-Access-Control/m-p/129584#M18978</link>
      <description>&lt;P&gt;&lt;SPAN&gt;sk42815 tells you how to replace implied rules my manually defined rules.&amp;nbsp;&lt;/SPAN&gt;For working S2S VPN, either just enable&amp;nbsp;&lt;STRONG&gt;Accept Remote Access control connections&lt;/STRONG&gt;&amp;nbsp;or use&amp;nbsp;&lt;SPAN&gt;sk42815 to create a manual rule instead !&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Sep 2021 15:02:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Disconnect-after-disabling-Accept-Remote-Access-Control/m-p/129584#M18978</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-09-16T15:02:27Z</dc:date>
    </item>
  </channel>
</rss>

