<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Connections to Checkpoint native services do not encrypt within the VPN for firewall management in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connections-to-Checkpoint-native-services-do-not-encrypt-within/m-p/248521#M48554</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hello, This SK is not accessible to me&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 09 May 2025 15:45:15 GMT</pubDate>
    <dc:creator>jarvis_dantsrib</dc:creator>
    <dc:date>2025-05-09T15:45:15Z</dc:date>
    <item>
      <title>Connections to Checkpoint native services do not encrypt within the VPN for firewall management</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connections-to-Checkpoint-native-services-do-not-encrypt-within/m-p/248481#M48540</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;Hello, I am facing a problem where connections on service port 18191 and Checkpoint native services are not encrypted within the VPN, as a consequence it is not possible to manage the firewall and install policy of the remote unit via LAN IP.&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;BR /&gt;&lt;BR /&gt;The interesting thing is that only Checkpoint service traffic is not encrypted, but ICMP, SSH, HTTPS and other non-native services are encrypted within the VPN.&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;BR /&gt;&lt;BR /&gt;It is possible to see that there is a match in implicit accept rules, but the traffic is encrypted.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 May 2025 05:06:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connections-to-Checkpoint-native-services-do-not-encrypt-within/m-p/248481#M48540</guid>
      <dc:creator>jarvis_dantsrib</dc:creator>
      <dc:date>2025-05-09T05:06:41Z</dc:date>
    </item>
    <item>
      <title>Re: Connections to Checkpoint native services do not encrypt within the VPN for firewall management</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connections-to-Checkpoint-native-services-do-not-encrypt-within/m-p/248482#M48541</link>
      <description>&lt;P&gt;This is by design, the CP service traffic is already encrypted and is required to be working to set up a VPN to a remote device over the internet as you need to install the policy to get the VPN going. As such we don't tunnel it by default. You can change this behaviour, but at your risk.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk104582" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk104582&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 May 2025 05:20:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connections-to-Checkpoint-native-services-do-not-encrypt-within/m-p/248482#M48541</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2025-05-09T05:20:40Z</dc:date>
    </item>
    <item>
      <title>Re: Connections to Checkpoint native services do not encrypt within the VPN for firewall management</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connections-to-Checkpoint-native-services-do-not-encrypt-within/m-p/248521#M48554</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello, This SK is not accessible to me&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 May 2025 15:45:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connections-to-Checkpoint-native-services-do-not-encrypt-within/m-p/248521#M48554</guid>
      <dc:creator>jarvis_dantsrib</dc:creator>
      <dc:date>2025-05-09T15:45:15Z</dc:date>
    </item>
    <item>
      <title>Re: Connections to Checkpoint native services do not encrypt within the VPN for firewall management</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connections-to-Checkpoint-native-services-do-not-encrypt-within/m-p/248528#M48559</link>
      <description>&lt;P&gt;The solution (and its implications) are discussed in these two CheckMates threads:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://community.checkpoint.com/t5/Management/Exclude-CPM-traffic-from-implied-rules/m-p/3934" target="_blank"&gt;https://community.checkpoint.com/t5/Management/Exclude-CPM-traffic-from-implied-rules/m-p/3934&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.checkpoint.com/t5/Management/Exclude-CPM-Traffic-from-Implied-Rules/m-p/9187" target="_blank"&gt;https://community.checkpoint.com/t5/Management/Exclude-CPM-Traffic-from-Implied-Rules/m-p/9187&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 May 2025 17:13:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connections-to-Checkpoint-native-services-do-not-encrypt-within/m-p/248528#M48559</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-05-09T17:13:10Z</dc:date>
    </item>
    <item>
      <title>Re: Connections to Checkpoint native services do not encrypt within the VPN for firewall management</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connections-to-Checkpoint-native-services-do-not-encrypt-within/m-p/272818#M103927</link>
      <description>&lt;P&gt;I don't know why but this SK doesn't work for R82 SMS and R81.20 GW configuration.&lt;BR /&gt;Right now, I've excluded next:&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;/*&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A title="#define" target="_blank"&gt;#define&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;ENABLE_CPMI */&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;/*&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A title="#define" target="_blank"&gt;#define&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;ENABLE_CPD */&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;/*&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A title="#define" target="_blank"&gt;#define&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;ENABLE_FWD_LOG */&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;And after policy installation I see same clear text traffic via VPNT interface.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2026 08:35:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connections-to-Checkpoint-native-services-do-not-encrypt-within/m-p/272818#M103927</guid>
      <dc:creator>akurtasanov</dc:creator>
      <dc:date>2026-03-09T08:35:06Z</dc:date>
    </item>
    <item>
      <title>Re: Connections to Checkpoint native services do not encrypt within the VPN for firewall management</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connections-to-Checkpoint-native-services-do-not-encrypt-within/m-p/272821#M103929</link>
      <description>&lt;P&gt;Please make sure you are editing the right instance of the file.&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SecurityManagement_AdminGuide/Content/Topics-SECMG/Configuring_Implied_Rules_or_Kernel_Tables_for_Security_Gateways_implied_rules.def.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SecurityManagement_AdminGuide/Content/Topics-SECMG/Configuring_Implied_Rules_or_Kernel_Tables_for_Security_Gateways_implied_rules.def.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2026 08:56:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connections-to-Checkpoint-native-services-do-not-encrypt-within/m-p/272821#M103929</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2026-03-09T08:56:35Z</dc:date>
    </item>
    <item>
      <title>Re: Connections to Checkpoint native services do not encrypt within the VPN for firewall management</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connections-to-Checkpoint-native-services-do-not-encrypt-within/m-p/273341#M104112</link>
      <description>&lt;P&gt;Yes, I checked. I contacted TAC but so far no results. Restarting the SMS didn't help either.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2026 08:02:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connections-to-Checkpoint-native-services-do-not-encrypt-within/m-p/273341#M104112</guid>
      <dc:creator>akurtasanov</dc:creator>
      <dc:date>2026-03-13T08:02:29Z</dc:date>
    </item>
  </channel>
</rss>

