<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: To block 18264 on CheckPoint External Firewall in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/To-block-18264-on-CheckPoint-External-Firewall/m-p/163875#M29257</link>
    <description>&lt;P&gt;Do you know if this is permanent point to point VPNs or the VPNs used on Checkpoint client connections on laptops?&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
    <pubDate>Thu, 01 Dec 2022 14:38:44 GMT</pubDate>
    <dc:creator>charles-corbin</dc:creator>
    <dc:date>2022-12-01T14:38:44Z</dc:date>
    <item>
      <title>To block 18264 on CheckPoint External Firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/To-block-18264-on-CheckPoint-External-Firewall/m-p/108587#M14657</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Need your guy's advice on how to block port 18264 on external interface of checkpoint firewall access.&lt;BR /&gt;As CheckPoint Support not recommended to disabled the "Accept Control Connection", it will&amp;nbsp;blocking traffic on this port can impact Firewall SMS communication, and VPN authentication among other services.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Understand that after&amp;nbsp;disabled the "Accept Control Connection", we can create explicit rules to control the traffic.&lt;/P&gt;&lt;P&gt;It will need a lot of effort on explicit rules since our SMS having more than 10 gateways.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Is there an alternative way to block&amp;nbsp;port 18264 ?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;We had tried below solution, however, it's still accessible to&amp;nbsp;port 18264 on external interface&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;-&amp;nbsp;&lt;SPAN&gt;Add an static NAT rule and NAT it to null IP (Implied rule goes first, so NATing is not working)&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/block-port-443-and-80-and-18264-on-checkpoint-external-firewall/td-p/80059" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/block-port-443-and-80-and-18264-on-checkpoint-external-firewall/td-p/80059&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- Manually change the implied_rule.def&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;-&amp;gt;&amp;nbsp;//#define ENABLE_PORTAL_HTTP_REDIRECT in implied rules&lt;SPAN&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/How-to-disable-Gaia-access-from-the-Internet/td-p/8227" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/How-to-disable-Gaia-access-from-the-Internet/td-p/8227&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-Modified the implied_rule.def&lt;BR /&gt;Change it to:&amp;nbsp;&amp;nbsp;&lt;EM&gt;// #define ENABLE_FW1_ICA_SERVICES&lt;/EM&gt;&lt;BR /&gt;(add // before #)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk35292" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk35292&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Kindly adsie on this.&lt;BR /&gt;&lt;BR /&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jan 2021 04:54:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/To-block-18264-on-CheckPoint-External-Firewall/m-p/108587#M14657</guid>
      <dc:creator>Bruce_Lee</dc:creator>
      <dc:date>2021-01-23T04:54:02Z</dc:date>
    </item>
    <item>
      <title>Re: To block 18264 on CheckPoint External Firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/To-block-18264-on-CheckPoint-External-Firewall/m-p/108592#M14660</link>
      <description>&lt;P&gt;What is the version of gateway and management in question?&lt;BR /&gt;Note if the gateway and management are different versions, you may have to apply this fix in multiple locations (i.e. in the various backward compatibility directories).&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jan 2021 06:48:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/To-block-18264-on-CheckPoint-External-Firewall/m-p/108592#M14660</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-23T06:48:47Z</dc:date>
    </item>
    <item>
      <title>Re: To block 18264 on CheckPoint External Firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/To-block-18264-on-CheckPoint-External-Firewall/m-p/108643#M14697</link>
      <description>&lt;P&gt;Personally, I would NEVER modify implied rules, thats a big security issue, at least for me. Also, how are you testing that access? via telnet or some other way? I would really like to see it for myself on the remote session if you are up for that, so you can show me exactly how this is configured.&lt;/P&gt;&lt;P&gt;Let me know.&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jan 2021 04:16:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/To-block-18264-on-CheckPoint-External-Firewall/m-p/108643#M14697</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-01-24T04:16:00Z</dc:date>
    </item>
    <item>
      <title>Re: To block 18264 on CheckPoint External Firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/To-block-18264-on-CheckPoint-External-Firewall/m-p/109631#M14953</link>
      <description>&lt;P&gt;I referred to sk105719 and blocked the 18264 port with /* */. (from implied_rule.def)&lt;BR /&gt;/* #define ENABLE_FW1_ICA_SERVICES */&lt;/P&gt;&lt;P&gt;If the version of the management server and gateway is different, refer to sk92281.&lt;BR /&gt;Blocking it is not recommended if you are using a VPN.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 06:23:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/To-block-18264-on-CheckPoint-External-Firewall/m-p/109631#M14953</guid>
      <dc:creator>SangJun</dc:creator>
      <dc:date>2021-02-03T06:23:54Z</dc:date>
    </item>
    <item>
      <title>Re: To block 18264 on CheckPoint External Firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/To-block-18264-on-CheckPoint-External-Firewall/m-p/163875#M29257</link>
      <description>&lt;P&gt;Do you know if this is permanent point to point VPNs or the VPNs used on Checkpoint client connections on laptops?&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 14:38:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/To-block-18264-on-CheckPoint-External-Firewall/m-p/163875#M29257</guid>
      <dc:creator>charles-corbin</dc:creator>
      <dc:date>2022-12-01T14:38:44Z</dc:date>
    </item>
    <item>
      <title>Re: To block 18264 on CheckPoint External Firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/To-block-18264-on-CheckPoint-External-Firewall/m-p/163886#M29262</link>
      <description>&lt;P&gt;It applies to both.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 15:18:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/To-block-18264-on-CheckPoint-External-Firewall/m-p/163886#M29262</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-12-01T15:18:40Z</dc:date>
    </item>
    <item>
      <title>Re: To block 18264 on CheckPoint External Firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/To-block-18264-on-CheckPoint-External-Firewall/m-p/189494#M34882</link>
      <description>&lt;P&gt;Apart from disabling the implied rule. Is there any alternative way for blocking the 18264 port for being accept through implied rule. Can we stop the service. (cpca_client set_ca_services off)&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2023 04:54:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/To-block-18264-on-CheckPoint-External-Firewall/m-p/189494#M34882</guid>
      <dc:creator>RBP</dc:creator>
      <dc:date>2023-08-15T04:54:54Z</dc:date>
    </item>
    <item>
      <title>Re: To block 18264 on CheckPoint External Firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/To-block-18264-on-CheckPoint-External-Firewall/m-p/189557#M34914</link>
      <description>&lt;P&gt;This is a required service and leaving it stopped will cause anything involving SIC and/or VPNs to eventually break.&lt;BR /&gt;Modifying implied rules is one option, another is to use fw samp to block the relevant traffic on each gateway, which are enforced before Implied Rules.&lt;BR /&gt;A command like the following will need to be executed on all relevant gateways:&amp;nbsp;fwaccel dos rate add -a d destination cidr:x.y.z.w/32 service 6/18264&lt;BR /&gt;This will block all traffic to the IP address x.y.z.w on TCP port 18264.&lt;BR /&gt;More details/specifics here:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk112454" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk112454&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2023 21:27:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/To-block-18264-on-CheckPoint-External-Firewall/m-p/189557#M34914</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-08-15T21:27:08Z</dc:date>
    </item>
    <item>
      <title>Re: To block 18264 on CheckPoint External Firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/To-block-18264-on-CheckPoint-External-Firewall/m-p/198485#M37158</link>
      <description>&lt;P&gt;sk35292 is not avalaible anymore.&lt;/P&gt;
&lt;P&gt;Refer to&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk179346" target="_blank" rel="noopener"&gt;sk179346: Configuring Explicit Rules instead of Implied Rules&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 09:24:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/To-block-18264-on-CheckPoint-External-Firewall/m-p/198485#M37158</guid>
      <dc:creator>Sergei_Shir</dc:creator>
      <dc:date>2023-11-21T09:24:34Z</dc:date>
    </item>
  </channel>
</rss>

