<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to disable Gaia access from the Internet in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/8228#M433</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To resolve this:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk105740" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk105740"&gt;HTTP and HTTPS requests to external interfaces create implied rule 0 accepts in SmartView Tracker&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 23 Nov 2018 18:01:25 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-11-23T18:01:25Z</dc:date>
    <item>
      <title>How to disable Gaia access from the Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/8227#M432</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have a typical policy that allows access to Gaia (https) from some internal machines, followed by a stealth rule that blocks all the other accesses (any-[sms, clusterxl and nodes]-drop).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Despite this, if I try to open a browser from an external machine, pointing to one of the public IPs (&lt;A href="https://publicIP"&gt;https://publicIP&lt;/A&gt;) of the cluster, I'm asked to accept the certificate.&lt;/P&gt;&lt;P&gt;I can't load the user/password page, but I need to avoid to even to show that something is listening.&lt;/P&gt;&lt;P&gt;The customer told me that in the past someone executed a command to block this access, but I was expecting that the policy was enough.&lt;/P&gt;&lt;P&gt;What is this command? I don't want to disable the Gaia Portal, just from the Internet.&lt;/P&gt;&lt;P&gt;Or there is a configuration in the Global Policy that I missed?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Nov 2018 14:06:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/8227#M432</guid>
      <dc:creator>Akira_Yagi</dc:creator>
      <dc:date>2018-11-23T14:06:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable Gaia access from the Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/8228#M433</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To resolve this:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk105740" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk105740"&gt;HTTP and HTTPS requests to external interfaces create implied rule 0 accepts in SmartView Tracker&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Nov 2018 18:01:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/8228#M433</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-11-23T18:01:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable Gaia access from the Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/8229#M434</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the answer but I'm not sure this SK is related to my problem.&lt;/P&gt;&lt;P&gt;What happens is that if I try to load the cluster public IP from, for example, my smartphone by using 4G data connection (just to say that I'm completely outside), I'm asked to accept the certificate for the &lt;A _jive_internal="true" href="https://community.checkpoint.com/[public_ip]"&gt;https://[public_ip]&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;If I go on, I can't load anything since I have a "any-[nodes/cluster]-drop" stealth rule.&lt;/P&gt;&lt;P&gt;But I need to avoid that Gaia WebUI responds at all from outside, I just want that if someone put my cluster's public IP in their browser, they have an error page.&lt;/P&gt;&lt;P&gt;Is not about seeing unwanted logs, people can actually understand that something is behind that IP..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Nov 2018 15:10:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/8229#M434</guid>
      <dc:creator>Akira_Yagi</dc:creator>
      <dc:date>2018-11-26T15:10:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable Gaia access from the Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/8230#M435</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is exactly related to the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To explain in a little more detail, there is something called multiportal that "multiplexes" access to the various web portals (Gaia, Mobile Access Blade, API, UserCheck, etc).&lt;/P&gt;&lt;P&gt;This allows discrete portals running different webservers to use the same IP/port combination with the difference being what URI is accessed.&lt;/P&gt;&lt;P&gt;A kernel-level process actually does the redirection, which means it's "always listening" on ports 80/443.&lt;/P&gt;&lt;P&gt;The only way to know what URI is accessed is to terminate the TCP connection.&lt;/P&gt;&lt;P&gt;Based on the configuration/security policy and the URI accessed, the connection will either be allowed/dropped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The SK tells you how to disable this.&lt;/P&gt;&lt;P&gt;The downside is you can't leverage Multiportal anymore and you must set each individual web portal to use a different IP/port combination.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Nov 2018 16:57:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/8230#M435</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-11-26T16:57:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable Gaia access from the Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/51591#M3892</link>
      <description>&lt;P&gt;It looks like the SK is only for the HTTP redirection, not the HTTPS issue :&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In order to stop the Security Gateway from responding to all TCP connections on port 80 (e.g., for PCI audits), edit the relevant 'implied_rules' file (refer to&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://supportcontent.checkpoint.com/solutions?id=sk92281" target="_blank" rel="noopener"&gt;sk92281&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;for locations) and install policy&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have tried this solution :&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;-&amp;gt; set the gaia portal to 4434&lt;/P&gt;&lt;P&gt;-&amp;gt; set allowed hosts in Gaia&lt;/P&gt;&lt;P&gt;-&amp;gt;&amp;nbsp;//#define ENABLE_PORTAL_HTTP_REDIRECT in implied rules&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTTP is now indeed not redirecting to HTTPS, and my connction to 4434 is working for my allowed hosts, but HTTPS is still poping up the certificate and so the gateway is still exposed on the internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2019 12:53:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/51591#M3892</guid>
      <dc:creator>Kristof_Vermael</dc:creator>
      <dc:date>2019-04-23T12:53:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable Gaia access from the Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/51746#M3899</link>
      <description>&lt;P&gt;Add an static NAT rule and NAT it to null IP:-)&lt;/P&gt;
&lt;P&gt;src: internet&lt;/P&gt;
&lt;P&gt;dst: portal ip&lt;/P&gt;
&lt;P&gt;port: portal port&lt;/P&gt;
&lt;P&gt;NAT src: internet&lt;/P&gt;
&lt;P&gt;NAT dst: static NAT to null IP for example 127.0.0.99&lt;/P&gt;
&lt;P&gt;NAT port: portal port&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2019 16:59:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/51746#M3899</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-04-24T16:59:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable Gaia access from the Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/51774#M3902</link>
      <description>&lt;P&gt;We have disabled WebUI and the problem is solved &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; What is the point to have WebUI in these days? Just one-time access for First Time Wizard...&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2019 19:50:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/51774#M3902</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2019-04-24T19:50:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable Gaia access from the Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/52404#M3969</link>
      <description>&lt;P&gt;Hello Heiko,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was in the assumption NAT rules do not work for implied rules, but i have tested your solution and it seems to be working just fine !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for this, this is a bit dirty solution to solve but I can live with this &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2019 11:02:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/52404#M3969</guid>
      <dc:creator>Kristof_Vermael</dc:creator>
      <dc:date>2019-05-02T11:02:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable Gaia access from the Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/52406#M3970</link>
      <description>&lt;P&gt;Additional question to this:&lt;/P&gt;&lt;P&gt;How do you specify the source object "Internet" in R77.x, in R80.x&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2019 11:24:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/52406#M3970</guid>
      <dc:creator>peter_schumache</dc:creator>
      <dc:date>2019-05-02T11:24:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable Gaia access from the Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/52408#M3971</link>
      <description>&lt;P&gt;In the access policy, I'm negating a group objects containing all internal en VPN subnets.&lt;/P&gt;&lt;P&gt;In the NAT policy, i'm using a NO NAT rule this group as source and as destination. All Internet nat rules are below this rule, all internet natting are above this rule.&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2019 11:47:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/52408#M3971</guid>
      <dc:creator>Kristof_Vermael</dc:creator>
      <dc:date>2019-05-02T11:47:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable Gaia access from the Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/52693#M4005</link>
      <description>&lt;P&gt;Based on some feedback, Check Point has changed the SK :&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk105740" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk105740&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2019 14:09:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/52693#M4005</guid>
      <dc:creator>Kristof_Vermael</dc:creator>
      <dc:date>2019-05-06T14:09:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable Gaia access from the Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/52698#M4006</link>
      <description>&lt;P&gt;Properly defining GAiA's hosts access is very important. Therefore I added a check to our &lt;A href="https://community.checkpoint.com/t5/General-Topics/Common-Check-Point-Commands-ccc/m-p/38488#M8207" target="_self"&gt;ccc script&lt;/A&gt; that will show in bold red letters when host access is set to Any.&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2019 14:58:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/52698#M4006</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2019-05-06T14:58:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable Gaia access from the Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/85856#M6626</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;The NAT configuration is the solution, but not a very nice one.&lt;/P&gt;&lt;P&gt;We have a customer with the same issue. He created certificates for the Gaia portal, but when someone access the appliances from the internet over HTTPS, the certificate is shown including information from the internal network (Root CA name etc.) This is not what the customer wants.&lt;/P&gt;&lt;P&gt;Does anyone know if a better solution has become available?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Martijn&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2020 09:29:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/85856#M6626</guid>
      <dc:creator>Martijn</dc:creator>
      <dc:date>2020-05-20T09:29:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable Gaia access from the Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/89654#M6863</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;From support I got an better solution that does not involve creating strange NAT configuration. Just edit the implied_rules.def file in $FWDIR/lib&lt;/P&gt;&lt;P&gt;From:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;// The following is for portals: http and https (80 and 443)&lt;/P&gt;&lt;P&gt;#if defined (ENABLE_PORTAL_HTTP_REDIRECT)&lt;/P&gt;&lt;P&gt;#define enable_portal_http(gw, ip_list, portals_allow_ext_ifc) \&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ((dport = 80) or (dport = 443)),&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; \&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ((portals_allow_ext_ifc = 0, ifaddr in internal_interface_list \&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ) or (portals_allow_ext_ifc = 1)),&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; \&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;dst&amp;gt; in ip_list, inbound, tcp,&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; \&lt;/P&gt;&lt;P&gt;&amp;nbsp; start_rule_code(MAKE_RULENUM(0,0x38)),&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; \&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; set r_entry CHANGE_TYPE(r_entry,CONN_NOENC),&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; \&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; set r_mhandler &amp;amp;tcpt_dummy_handler,&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; \&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; IMPLIED_RECORD_CONN(MAKE_RULENUM(0,0x38)), \&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; IMPLIED_LOG, accept;&lt;/P&gt;&lt;P&gt;#else&lt;/P&gt;&lt;P&gt;#define enable_portal_http(gw, ip_list, portals_allow_ext_ifc)&lt;/P&gt;&lt;P&gt;#endif&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TO:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;// The following is for portals: http and https (80 and 443)&lt;/P&gt;&lt;P&gt;#if defined (ENABLE_PORTAL_HTTP_REDIRECT)&lt;/P&gt;&lt;P&gt;#define enable_portal_http(gw, ip_list, portals_allow_ext_ifc) \&lt;/P&gt;&lt;P&gt;&amp;nbsp;/*&amp;nbsp;&amp;nbsp; ((dport = 80) or (dport = 443)),&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;\&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ((portals_allow_ext_ifc = 0, ifaddr in internal_interface_list \&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ) or (portals_allow_ext_ifc = 1)),&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; \&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;dst&amp;gt; in ip_list, inbound, tcp,&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; \&lt;/P&gt;&lt;P&gt;&amp;nbsp; start_rule_code(MAKE_RULENUM(0,0x38)),&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;\&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; set r_entry CHANGE_TYPE(r_entry,CONN_NOENC),&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; \&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; set r_mhandler &amp;amp;tcpt_dummy_handler,&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; \&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; IMPLIED_RECORD_CONN(MAKE_RULENUM(0,0x38)), \&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; IMPLIED_LOG, accept; */&lt;/P&gt;&lt;P&gt;#else&lt;/P&gt;&lt;P&gt;#define enable_portal_http(gw, ip_list, portals_allow_ext_ifc)&lt;/P&gt;&lt;P&gt;#endif&lt;/P&gt;&lt;P&gt;After this, you need to create explicit rule to allow the required traffic, but the certificate is not shown anymore.&lt;/P&gt;&lt;P&gt;In my lab and at the customers gateway, this was to solution.&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Martijn&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2020 08:02:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/89654#M6863</guid>
      <dc:creator>Martijn</dc:creator>
      <dc:date>2020-06-24T08:02:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable Gaia access from the Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/104706#M8280</link>
      <description>&lt;P&gt;How do I access the above to make the needed change?&amp;nbsp; A file using vi editor?&amp;nbsp; I believe I am having the exact same problem with the ICA certificate showing on the public internet via https.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 21:23:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/104706#M8280</guid>
      <dc:creator>Mike_Jensen</dc:creator>
      <dc:date>2020-12-08T21:23:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable Gaia access from the Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/104720#M8284</link>
      <description>&lt;P&gt;Yes, in expert mode run:&amp;nbsp;&lt;SPAN&gt;$FWDIR/lib/implied_rules.def&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I suggest to read &lt;A href="https://community.checkpoint.com/t5/General-Topics/HowTo-React-on-Check-Point-Information-Disclosure/td-p/9773" target="_self"&gt;this article&lt;/A&gt; as well.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 04:06:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/104720#M8284</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2020-12-09T04:06:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable Gaia access from the Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/210957#M39967</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;old thread, I know.&lt;/P&gt;
&lt;P&gt;However, did you just disabled the start of&amp;nbsp;httpd2 or is there a better solution?&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 16:03:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/210957#M39967</guid>
      <dc:creator>S_E_</dc:creator>
      <dc:date>2024-04-10T16:03:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable Gaia access from the Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/210959#M39968</link>
      <description>&lt;P&gt;clish command "set web&amp;nbsp;daemon-enable off".&lt;/P&gt;
&lt;P&gt;If you are using management, disabling webUI on management will cause API stopped working.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 20:17:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/210959#M39968</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2024-04-10T20:17:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable Gaia access from the Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/233279#M45116</link>
      <description>&lt;P&gt;Is a reboot or policy install required after making this change?&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I edited my implied_rules.def file accordingly but I can still see the certificate from the public internet.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2024 15:24:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/233279#M45116</guid>
      <dc:creator>Mike_Jensen</dc:creator>
      <dc:date>2024-11-20T15:24:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable Gaia access from the Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/233303#M45127</link>
      <description>&lt;P&gt;You need to install policy.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2024 17:11:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-Gaia-access-from-the-Internet/m-p/233303#M45127</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2024-11-20T17:11:16Z</dc:date>
    </item>
  </channel>
</rss>

