<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Port 80, 443, 500 and 18264 are open on external interfaces, how to block it? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Port-80-443-500-and-18264-are-open-on-external-interfaces-how-to/m-p/255929#M50123</link>
    <description>&lt;P&gt;If you have any VPNs, port 18264 needs to be open for the CRL to validate VPN certificates.&lt;BR /&gt;If you do NOT have any Remote Access VPN users, then you could theoretically disable access on port 80/443.&lt;BR /&gt;UDP 500 is needed for any sort of VPN.&lt;/P&gt;</description>
    <pubDate>Mon, 25 Aug 2025 18:45:08 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2025-08-25T18:45:08Z</dc:date>
    <item>
      <title>Port 80, 443, 500 and 18264 are open on external interfaces, how to block it?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Port-80-443-500-and-18264-are-open-on-external-interfaces-how-to/m-p/255784#M50073</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Our vulnerability scanner shown port 80, 443, 500 and 18264 are open on external interfaces of our firewall. We are not using SSL VPN or remote access VPN on this firewall but we have IPSec Site to Site VPN Tunnel on it. I have disabled few settings&amp;nbsp;&lt;/P&gt;&lt;P&gt;- VPN Clients &amp;gt; Desktops / Laptops Windows and Mac clients&lt;/P&gt;&lt;P&gt;- VPN Clients &amp;gt; Authentication &amp;gt; allow older client to connect this gateway&lt;/P&gt;&lt;P&gt;- VPN Client &amp;gt; Remote Access &amp;gt; Allow remote clients to route the traffic through this gateway&lt;/P&gt;&lt;P&gt;- Mobile Access &amp;gt; Web - SSL vpn with Web Browser&lt;/P&gt;&lt;P&gt;But still the above mentioned ports are open and as per SOC team they are insisting me to block access to this ports from the external word. I need help here can anyone please suggest what needs to be done fix this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Aug 2025 06:09:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Port-80-443-500-and-18264-are-open-on-external-interfaces-how-to/m-p/255784#M50073</guid>
      <dc:creator>Deepraj_Patil</dc:creator>
      <dc:date>2025-08-23T06:09:02Z</dc:date>
    </item>
    <item>
      <title>Re: Port 80, 443, 500 and 18264 are open on external interfaces, how to block it?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Port-80-443-500-and-18264-are-open-on-external-interfaces-how-to/m-p/255786#M50075</link>
      <description>&lt;P&gt;If you have S2S VPN you probably don't want to block 500.&lt;/P&gt;
&lt;P&gt;Solutions for the others are readily searchable.&lt;/P&gt;</description>
      <pubDate>Sat, 23 Aug 2025 06:31:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Port-80-443-500-and-18264-are-open-on-external-interfaces-how-to/m-p/255786#M50075</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-08-23T06:31:00Z</dc:date>
    </item>
    <item>
      <title>Re: Port 80, 443, 500 and 18264 are open on external interfaces, how to block it?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Port-80-443-500-and-18264-are-open-on-external-interfaces-how-to/m-p/255929#M50123</link>
      <description>&lt;P&gt;If you have any VPNs, port 18264 needs to be open for the CRL to validate VPN certificates.&lt;BR /&gt;If you do NOT have any Remote Access VPN users, then you could theoretically disable access on port 80/443.&lt;BR /&gt;UDP 500 is needed for any sort of VPN.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Aug 2025 18:45:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Port-80-443-500-and-18264-are-open-on-external-interfaces-how-to/m-p/255929#M50123</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-08-25T18:45:08Z</dc:date>
    </item>
    <item>
      <title>Re: Port 80, 443, 500 and 18264 are open on external interfaces, how to block it?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Port-80-443-500-and-18264-are-open-on-external-interfaces-how-to/m-p/256243#M50191</link>
      <description>&lt;P&gt;Make a fake NAT rule to any sort of 127.0.0.x &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Aug 2025 14:51:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Port-80-443-500-and-18264-are-open-on-external-interfaces-how-to/m-p/256243#M50191</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2025-08-30T14:51:55Z</dc:date>
    </item>
    <item>
      <title>Re: Port 80, 443, 500 and 18264 are open on external interfaces, how to block it?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Port-80-443-500-and-18264-are-open-on-external-interfaces-how-to/m-p/256245#M50192</link>
      <description>&lt;P data-start="47" data-end="124"&gt;HI&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/108310"&gt;@Deepraj_Patil&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;The following overview shows all open ports used by a Check Point gateway and management server.&lt;BR /&gt;&lt;A href="https://www.checkpoint.tips/doc/Ports.pdf" target="_blank" rel="noopener"&gt;https://www.checkpoint.tips/doc/Ports.pdf&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Here is a picture (the same one can be found in the PDF)&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Ports1_4534534.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31335i79E80EB1AD3AAADB/image-size/large?v=v2&amp;amp;px=999" role="button" title="Ports1_4534534.png" alt="Ports1_4534534.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Open Ports:&lt;BR /&gt;&lt;SPAN class="lia-message-unread lia-message-unread-windows"&gt;80&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; -&amp;gt; You should check this out (Static NAT to a web server , ...)&lt;BR /&gt;443&amp;nbsp; &amp;nbsp; &amp;nbsp; -&amp;gt; Multi Portal Daemon, Mobile Access Blade, Remote Access VPN,&amp;nbsp;(Static NAT to a web server , ...)&lt;BR /&gt;500&amp;nbsp; &amp;nbsp; &amp;nbsp; -&amp;gt; IPSec VPN&lt;BR /&gt;18264&amp;nbsp; -&amp;gt; VPN Cert. fetch&lt;BR /&gt;&lt;BR /&gt;In addition to UDP 500, the &lt;STRONG data-start="28" data-end="45"&gt;UDP port 4500&lt;/STRONG&gt; may also need to be open for NAT-T, ensuring VPN connections work properly when endpoints are behind NAT devices.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Here's what you can do:&lt;/STRONG&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL data-start="126" data-end="248"&gt;
&lt;LI data-start="167" data-end="248"&gt;
&lt;P data-start="169" data-end="248"&gt;Change the position of rule processing under "&lt;STRONG data-start="214" data-end="246"&gt;Global Properties → Firewall"&amp;nbsp;&lt;/STRONG&gt;to "befor last" (Please proceed with caution)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="167" data-end="248"&gt;
&lt;P data-start="47" data-end="124"&gt;Create stealth rules on the firewall to block specific ports and access attempts.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Sat, 30 Aug 2025 16:50:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Port-80-443-500-and-18264-are-open-on-external-interfaces-how-to/m-p/256245#M50192</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2025-08-30T16:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: Port 80, 443, 500 and 18264 are open on external interfaces, how to block it?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Port-80-443-500-and-18264-are-open-on-external-interfaces-how-to/m-p/256263#M50196</link>
      <description>&lt;P&gt;Hi Heiko,&lt;/P&gt;&lt;P&gt;Thank you for the detailed information about the open ports.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Deepraj&lt;/P&gt;</description>
      <pubDate>Sun, 31 Aug 2025 16:35:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Port-80-443-500-and-18264-are-open-on-external-interfaces-how-to/m-p/256263#M50196</guid>
      <dc:creator>Deepraj_Patil</dc:creator>
      <dc:date>2025-08-31T16:35:53Z</dc:date>
    </item>
  </channel>
</rss>

