<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Check Point Supposed Vulnerabilities in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Supposed-Vulnerabilities/m-p/166798#M30028</link>
    <description>&lt;P&gt;Agree with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;&amp;nbsp;. Yes, you can use same cert, but its probably better practise to use different ones.&lt;/P&gt;</description>
    <pubDate>Thu, 05 Jan 2023 14:03:07 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-01-05T14:03:07Z</dc:date>
    <item>
      <title>Check Point Supposed Vulnerabilities</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Supposed-Vulnerabilities/m-p/166618#M29990</link>
      <description>&lt;P&gt;Hello Mates!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a case that I would like your help to know what I can do about it...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a customer that is a Financial Corporate. They have a GW in their environment with the latest updates (R81.10 T81 (a VM)).&lt;/P&gt;&lt;P&gt;A few days ago a company did some tests (I'm not sure about how this was done) and sent us a sheet with some "vulnerabilities" found in the gateway.&lt;/P&gt;&lt;P&gt;But the part that I was in doubt about was those recommendations below:&lt;/P&gt;&lt;P&gt;How can I "install a server certificate" on gateway? What does it mean exactly?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your support!&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2023 19:49:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Supposed-Vulnerabilities/m-p/166618#M29990</guid>
      <dc:creator>Bernardes</dc:creator>
      <dc:date>2023-01-03T19:49:11Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Supposed Vulnerabilities</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Supposed-Vulnerabilities/m-p/166619#M29991</link>
      <description>&lt;P&gt;Is customer using https inspection?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2023 20:58:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Supposed-Vulnerabilities/m-p/166619#M29991</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-03T20:58:54Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Supposed Vulnerabilities</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Supposed-Vulnerabilities/m-p/166621#M29993</link>
      <description>&lt;P&gt;It probably does not like a self-signed certificate on the gaia admin portal.&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk97648" target="_blank"&gt;How to create and configure certificate for Gaia Portal (checkpoint.com)&lt;/A&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2023 21:07:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Supposed-Vulnerabilities/m-p/166621#M29993</guid>
      <dc:creator>Lloyd_Braun</dc:creator>
      <dc:date>2023-01-03T21:07:01Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Supposed Vulnerabilities</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Supposed-Vulnerabilities/m-p/166622#M29994</link>
      <description>&lt;P&gt;Excellent point indeed.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2023 21:16:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Supposed-Vulnerabilities/m-p/166622#M29994</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-03T21:16:22Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Supposed Vulnerabilities</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Supposed-Vulnerabilities/m-p/166635#M29995</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;that feature is disabled on this gateway.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2023 00:57:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Supposed-Vulnerabilities/m-p/166635#M29995</guid>
      <dc:creator>Bernardes</dc:creator>
      <dc:date>2023-01-04T00:57:38Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Supposed Vulnerabilities</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Supposed-Vulnerabilities/m-p/166636#M29996</link>
      <description>&lt;P&gt;hello,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8834"&gt;@Lloyd_Braun&lt;/a&gt;&amp;nbsp;there's no certificate to access gaia portal indeed. Can it be the cause for these vulnerabilities found ?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2023 00:59:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Supposed-Vulnerabilities/m-p/166636#M29996</guid>
      <dc:creator>Bernardes</dc:creator>
      <dc:date>2023-01-04T00:59:19Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Supposed Vulnerabilities</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Supposed-Vulnerabilities/m-p/166637#M29997</link>
      <description>&lt;P&gt;I am pretty sure&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8834"&gt;@Lloyd_Braun&lt;/a&gt;&amp;nbsp;got it right, makes perfect sense.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2023 01:50:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Supposed-Vulnerabilities/m-p/166637#M29997</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-04T01:50:02Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Supposed Vulnerabilities</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Supposed-Vulnerabilities/m-p/166639#M29998</link>
      <description>&lt;P&gt;Implied rules will always allow port 80 and 443 connections to the firewall itself via multiportal, even if there is no feature enabled to actually talk to and exploit.&amp;nbsp; If this is unacceptable you can do the following, but bear in mind this will break any kind of Remote Access VPN access:&lt;/P&gt;
&lt;P&gt;1) Create an indefinite SAM rule from the SmartView Monitor or via the &lt;STRONG&gt;fw sam&lt;/STRONG&gt; command blocking connections with a destination of the firewall's outside IP on ports 80 and 443&lt;/P&gt;
&lt;P&gt;2) See&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk165937&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;sk165937: How to disable the connection to Security Gateway on TCP Port 80 and on TCP Port 443&lt;/A&gt;&amp;nbsp;to disable the implied rule completely&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2023 03:26:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Supposed-Vulnerabilities/m-p/166639#M29998</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-01-04T03:26:55Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Supposed Vulnerabilities</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Supposed-Vulnerabilities/m-p/166656#M30001</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/82249"&gt;@Bernardes&lt;/a&gt;&amp;nbsp;the gateways runs MultiPortal mentioned by&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;. There are several places to replace the default self signed certificates to one trusted by a known CA.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2023-01-04 08_26_50-Check Point Gateway - Corporate-GW.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18989i6D59C7BF6C1AA3D7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2023-01-04 08_26_50-Check Point Gateway - Corporate-GW.png" alt="2023-01-04 08_26_50-Check Point Gateway - Corporate-GW.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2023-01-04 08_26_13-Check Point Gateway - Corporate-GW.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18991i1B8FBEF5A63004CF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2023-01-04 08_26_13-Check Point Gateway - Corporate-GW.png" alt="2023-01-04 08_26_13-Check Point Gateway - Corporate-GW.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2023-01-04 08_25_25-Check Point Gateway - Corporate-GW.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18990i935755A75EF5D25D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2023-01-04 08_25_25-Check Point Gateway - Corporate-GW.png" alt="2023-01-04 08_25_25-Check Point Gateway - Corporate-GW.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Here you can change the supported TLS version:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="2023-01-04 08_28_27-AdvancedConfiguration.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18993i9FCEE3A4A914C371/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2023-01-04 08_28_27-AdvancedConfiguration.png" alt="2023-01-04 08_28_27-AdvancedConfiguration.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2023 07:39:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Supposed-Vulnerabilities/m-p/166656#M30001</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2023-01-04T07:39:36Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Supposed Vulnerabilities</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Supposed-Vulnerabilities/m-p/166674#M30008</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;&amp;nbsp;&amp;nbsp;thank you for your advice!&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2023 13:33:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Supposed-Vulnerabilities/m-p/166674#M30008</guid>
      <dc:creator>Bernardes</dc:creator>
      <dc:date>2023-01-04T13:33:34Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Supposed Vulnerabilities</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Supposed-Vulnerabilities/m-p/166675#M30009</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;thank you very much for the tip!&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2023 13:34:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Supposed-Vulnerabilities/m-p/166675#M30009</guid>
      <dc:creator>Bernardes</dc:creator>
      <dc:date>2023-01-04T13:34:22Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Supposed Vulnerabilities</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Supposed-Vulnerabilities/m-p/166678#M30010</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;&amp;nbsp;just a question... All these portals require a different certificate for each one or can it be the same SSL certificate for all?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2023 14:16:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Supposed-Vulnerabilities/m-p/166678#M30010</guid>
      <dc:creator>Bernardes</dc:creator>
      <dc:date>2023-01-04T14:16:19Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Supposed Vulnerabilities</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Supposed-Vulnerabilities/m-p/166793#M30026</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/82249"&gt;@Bernardes&lt;/a&gt;&amp;nbsp;from a technical point of view you can use the same certificate for all if it matches the names/ip-addresses. But it's used for different needs. One for MobileAccessPortal, one for GAiA WebUI the platform portal and one for UserCheck webpage. Typically we are using different certificates.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 13:49:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Supposed-Vulnerabilities/m-p/166793#M30026</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2023-01-05T13:49:52Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Supposed Vulnerabilities</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Supposed-Vulnerabilities/m-p/166798#M30028</link>
      <description>&lt;P&gt;Agree with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;&amp;nbsp;. Yes, you can use same cert, but its probably better practise to use different ones.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 14:03:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Supposed-Vulnerabilities/m-p/166798#M30028</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-05T14:03:07Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Supposed Vulnerabilities</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Supposed-Vulnerabilities/m-p/166801#M30029</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;&amp;nbsp;Thank you for all! You help me a lot!&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 14:12:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Supposed-Vulnerabilities/m-p/166801#M30029</guid>
      <dc:creator>Bernardes</dc:creator>
      <dc:date>2023-01-05T14:12:25Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Supposed Vulnerabilities</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Supposed-Vulnerabilities/m-p/166804#M30030</link>
      <description>&lt;P&gt;We are here to help...happy new year!!&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 14:14:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Supposed-Vulnerabilities/m-p/166804#M30030</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-05T14:14:39Z</dc:date>
    </item>
  </channel>
</rss>

