<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: vpnd process running, vpn blade not enabled in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpnd-process-running-vpn-blade-not-enabled/m-p/158816#M27740</link>
    <description>&lt;P&gt;It is related to other Portals:&lt;/P&gt;
&lt;P&gt;"&lt;SPAN&gt;As well as establishing Site-to-Site and Remote Access VPN, the VPND process is also responsible for presenting the certificates used for Portals, other the the Platform Portal"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk109172" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk109172&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 05 Oct 2022 10:40:46 GMT</pubDate>
    <dc:creator>Tal_Paz-Fridman</dc:creator>
    <dc:date>2022-10-05T10:40:46Z</dc:date>
    <item>
      <title>vpnd process running, vpn blade not enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpnd-process-running-vpn-blade-not-enabled/m-p/158779#M27733</link>
      <description>&lt;P&gt;A question that has bothered me for some time. I have a gateway (cluster) with FW, IA, ClusterXL, Monitoring, and IPS blades enabled. ps shows the vpnd process running, netstat shows it listening on several VPN specific ports:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vpn1.jpg" style="width: 829px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18013i9EECCD8316AF040D/image-size/large?v=v2&amp;amp;px=999" role="button" title="vpn1.jpg" alt="vpn1.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I'm looking for an explanation...sk177128 hints that vpnd may be running for Multiportal. pstree really isn't too much help as to what starts it up:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pstree.jpg" style="width: 567px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18014iC1F8D0CAF5982622/image-size/large?v=v2&amp;amp;px=999" role="button" title="pstree.jpg" alt="pstree.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Is there any official sk, documentation, whatever that would explain why/what triggers the use of vpnd? We have compliance requirements to document all required services and listening ports.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2022 18:39:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpnd-process-running-vpn-blade-not-enabled/m-p/158779#M27733</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2022-10-04T18:39:30Z</dc:date>
    </item>
    <item>
      <title>Re: vpnd process running, vpn blade not enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpnd-process-running-vpn-blade-not-enabled/m-p/158781#M27734</link>
      <description>&lt;P&gt;Not sure on official documentation but in this case I can say it is because you have Identity Awareness enabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tim&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2022 20:28:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpnd-process-running-vpn-blade-not-enabled/m-p/158781#M27734</guid>
      <dc:creator>Tim_Koopman</dc:creator>
      <dc:date>2022-10-04T20:28:57Z</dc:date>
    </item>
    <item>
      <title>Re: vpnd process running, vpn blade not enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpnd-process-running-vpn-blade-not-enabled/m-p/158794#M27735</link>
      <description>&lt;P&gt;Are you using the "Identity Agent" with Identity Awareness in your environment?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2022 03:31:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpnd-process-running-vpn-blade-not-enabled/m-p/158794#M27735</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-10-05T03:31:53Z</dc:date>
    </item>
    <item>
      <title>Re: vpnd process running, vpn blade not enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpnd-process-running-vpn-blade-not-enabled/m-p/158816#M27740</link>
      <description>&lt;P&gt;It is related to other Portals:&lt;/P&gt;
&lt;P&gt;"&lt;SPAN&gt;As well as establishing Site-to-Site and Remote Access VPN, the VPND process is also responsible for presenting the certificates used for Portals, other the the Platform Portal"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk109172" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk109172&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2022 10:40:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpnd-process-running-vpn-blade-not-enabled/m-p/158816#M27740</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2022-10-05T10:40:46Z</dc:date>
    </item>
    <item>
      <title>Re: vpnd process running, vpn blade not enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpnd-process-running-vpn-blade-not-enabled/m-p/158825#M27741</link>
      <description>&lt;P&gt;No, only using Identity Collectors in our environment.&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2022 12:25:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpnd-process-running-vpn-blade-not-enabled/m-p/158825#M27741</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2022-10-05T12:25:06Z</dc:date>
    </item>
    <item>
      <title>Re: vpnd process running, vpn blade not enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpnd-process-running-vpn-blade-not-enabled/m-p/158830#M27743</link>
      <description>&lt;P&gt;Thanks everyone for the information. Putting some more pieces together, it seems:&lt;/P&gt;
&lt;P&gt;1. vpnd is used for Multiportal functionality&lt;/P&gt;
&lt;P&gt;2. Multiportal functionality is enabled if a) Identity Awareness is enabled and/or b) the Gaia portal is configured to use 443. I base b) off of a statement in sk115732:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sk115732.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18023i23B9009E88BB25D5/image-size/large?v=v2&amp;amp;px=999" role="button" title="sk115732.jpg" alt="sk115732.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;3. I have Identity Awareness enabled on this gateway and 443 is used for the Gaia portal.&amp;nbsp; Even though I am not using captive portal or usercheck on this gateway, Multiportal is enabled, though only one portal configured:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mpclient.jpg" style="width: 862px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18024iB29655772F2A357B/image-size/large?v=v2&amp;amp;px=999" role="button" title="mpclient.jpg" alt="mpclient.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;4. If vpnd is running (due to the above circumstances) it will still listen on traditional vpn ports (e.g. TCP 500) even though vpn blade is not enabled (this seems dumb, but is what it is).&lt;/P&gt;
&lt;P&gt;Based on this sleuthing (and other similar rabbit holes I have gone down) I'll say Check Point's documentation on services/daemons and network ports used by products has improved, but there's much room for improvement. In the regulatory world that I live in (and I'm guessing many others reading this) we are required to have detailed documentation of running processes/services and network listening ports on critical systems. If there were better documentation around this, it would have saved me a lot of time.&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2022 12:57:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpnd-process-running-vpn-blade-not-enabled/m-p/158830#M27743</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2022-10-05T12:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: vpnd process running, vpn blade not enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpnd-process-running-vpn-blade-not-enabled/m-p/158835#M27745</link>
      <description>&lt;P&gt;Adding a little more information - I examined another gateway that only has FW and Monitoring blades enabled (no IA). 443 is used for the Gaia portal. Multiportal is running, but the vpnd process is not:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vpnd2.jpg" style="width: 824px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18025i6059B23C45589B64/image-size/large?v=v2&amp;amp;px=999" role="button" title="vpnd2.jpg" alt="vpnd2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Based on this I'd say that the vpnd process will run only if IA is running. Multiportal running is not sufficient for vpnd to be started.&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2022 13:16:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/vpnd-process-running-vpn-blade-not-enabled/m-p/158835#M27745</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2022-10-05T13:16:35Z</dc:date>
    </item>
  </channel>
</rss>

