<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enable any port on Register to Hotspot (SmartEndpoint or Global Properties) in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Enable-any-port-on-Register-to-Hotspot-SmartEndpoint-or-Global/m-p/105182#M2837</link>
    <description>&lt;P&gt;Off topic, but on the global properties, remote access, hotspot / wifi registration section, where have you found the LOG for tracking? I thought it would be automatically sent up to the management server however unable to find it in the LOGS. Does anybody know where this LOG tracking entry is?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 11 Dec 2020 19:48:25 GMT</pubDate>
    <dc:creator>514numbers</dc:creator>
    <dc:date>2020-12-11T19:48:25Z</dc:date>
    <item>
      <title>Enable any port on Register to Hotspot (SmartEndpoint or Global Properties)</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Enable-any-port-on-Register-to-Hotspot-SmartEndpoint-or-Global/m-p/69892#M1837</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We are using Endpoint Security clients from E80.87 to E82.10, on approximately 1000 users. Our firewall gateway is on version R80.30, and our Endpoint Security Management Server is also on R80.30 (with two external Endpoint Policy Servers). As we have a lot of roaming users we need the ability to use the Register to Hotspot functionality with all ports open during the registration.&lt;/P&gt;&lt;P&gt;I followed the&amp;nbsp;&lt;SPAN&gt;sk41586 and defined the any_port through&amp;nbsp;&lt;/SPAN&gt;GuiDBedit tool, and applied it on the Global Properties (see attachment below) on the firewall gateway.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GP.jpg" style="width: 592px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/3603i85AB8AF5F1AA9499/image-dimensions/592x622?v=v2" width="592" height="622" role="button" title="GP.jpg" alt="GP.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But, as we are using the SmartEndpoint console, there is also the ability to define the ports to be used for Hotspot registration (Policy -&amp;gt; Allow hotspot registration). &lt;STRONG&gt;How can I define the any_port through SmartEndpoint, what value do I have to use (see attachment below)&lt;/STRONG&gt;? There is no description in the admin guide what to use for any port if you define it through SmartEndpoint.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SE.jpg" style="width: 505px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/3604iB0D4465DD448DA0C/image-dimensions/505x400?v=v2" width="505" height="400" role="button" title="SE.jpg" alt="SE.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And the thing that confuses me the most. &lt;STRONG&gt;What configuration will be applied on the client side when connected to VPN, the one defined on the gateway in Global Properties or the one defined in the SmartEndpoint Policy?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below is the configuration I get in trac.config when I connect to the VPN:&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&amp;lt;PARAM fw_hotspot_ports="&amp;amp;lt;any_port&amp;gt;"&amp;gt;&amp;lt;/PARAM&amp;gt;&lt;BR /&gt;&amp;lt;PARAM fw_hotspot_ports="443"&amp;gt;&amp;lt;/PARAM&amp;gt;&lt;BR /&gt;&amp;lt;PARAM fw_hotspot_ports="80"&amp;gt;&amp;lt;/PARAM&amp;gt;&lt;BR /&gt;&amp;lt;PARAM fw_hotspot_ports="8080"&amp;gt;&amp;lt;/PARAM&amp;gt;&lt;BR /&gt;&amp;lt;PARAM fw_hotspot_ports="8080"&amp;gt;&amp;lt;/PARAM&amp;gt;&lt;BR /&gt;&amp;lt;PARAM fw_hotspot_ports="8444"&amp;gt;&amp;lt;/PARAM&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Hrvoje&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2019 13:58:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Enable-any-port-on-Register-to-Hotspot-SmartEndpoint-or-Global/m-p/69892#M1837</guid>
      <dc:creator>Hrvoje_Brlek</dc:creator>
      <dc:date>2019-12-10T13:58:14Z</dc:date>
    </item>
    <item>
      <title>Re: Enable any port on Register to Hotspot (SmartEndpoint or Global Properties)</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Enable-any-port-on-Register-to-Hotspot-SmartEndpoint-or-Global/m-p/69924#M1842</link>
      <description>Maybe try a port range 1-65535?</description>
      <pubDate>Tue, 10 Dec 2019 18:11:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Enable-any-port-on-Register-to-Hotspot-SmartEndpoint-or-Global/m-p/69924#M1842</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-12-10T18:11:19Z</dc:date>
    </item>
    <item>
      <title>Re: Enable any port on Register to Hotspot (SmartEndpoint or Global Properties)</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Enable-any-port-on-Register-to-Hotspot-SmartEndpoint-or-Global/m-p/70026#M1844</link>
      <description>&lt;P&gt;Already tried, it doesn't accept any kind of port range:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="port.jpg" style="width: 588px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/3648iDDAE47F5D28FD19D/image-size/large?v=v2&amp;amp;px=999" role="button" title="port.jpg" alt="port.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is also&amp;nbsp;&lt;SPAN&gt;sk155072 which states the format above should work, but it doesn't (I tried while we were on R70.30.03 and now on R80.30):&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="port_range.JPG" style="width: 709px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/3649i97D5D51B62EF8445/image-size/large?v=v2&amp;amp;px=999" role="button" title="port_range.JPG" alt="port_range.JPG" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2019 08:15:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Enable-any-port-on-Register-to-Hotspot-SmartEndpoint-or-Global/m-p/70026#M1844</guid>
      <dc:creator>Hrvoje_Brlek</dc:creator>
      <dc:date>2019-12-11T08:15:11Z</dc:date>
    </item>
    <item>
      <title>Re: Enable any port on Register to Hotspot (SmartEndpoint or Global Properties)</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Enable-any-port-on-Register-to-Hotspot-SmartEndpoint-or-Global/m-p/70144#M1849</link>
      <description>If the SK says it should work and it doesn’t…probably worth a TAC case to clarify.</description>
      <pubDate>Wed, 11 Dec 2019 16:41:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Enable-any-port-on-Register-to-Hotspot-SmartEndpoint-or-Global/m-p/70144#M1849</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-12-11T16:41:12Z</dc:date>
    </item>
    <item>
      <title>Re: Enable any port on Register to Hotspot (SmartEndpoint or Global Properties)</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Enable-any-port-on-Register-to-Hotspot-SmartEndpoint-or-Global/m-p/70171#M1850</link>
      <description>Checked with R&amp;amp;D, this is most definitely a GUI bug.&lt;BR /&gt;Please open a TAC case.</description>
      <pubDate>Wed, 11 Dec 2019 20:13:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Enable-any-port-on-Register-to-Hotspot-SmartEndpoint-or-Global/m-p/70171#M1850</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-12-11T20:13:07Z</dc:date>
    </item>
    <item>
      <title>Re: Enable any port on Register to Hotspot (SmartEndpoint or Global Properties)</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Enable-any-port-on-Register-to-Hotspot-SmartEndpoint-or-Global/m-p/70216#M1851</link>
      <description>&lt;P&gt;OK, thanks, will do so &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2019 07:12:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Enable-any-port-on-Register-to-Hotspot-SmartEndpoint-or-Global/m-p/70216#M1851</guid>
      <dc:creator>Hrvoje_Brlek</dc:creator>
      <dc:date>2019-12-12T07:12:01Z</dc:date>
    </item>
    <item>
      <title>Re: Enable any port on Register to Hotspot (SmartEndpoint or Global Properties)</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Enable-any-port-on-Register-to-Hotspot-SmartEndpoint-or-Global/m-p/72854#M1926</link>
      <description>hi&lt;BR /&gt;any news about this issue? i have the same problem that i cannot configure an port-range.&lt;BR /&gt;next question is - do i have to configure global properties and/or hotspot-policy in endpoint-console?</description>
      <pubDate>Tue, 21 Jan 2020 14:05:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Enable-any-port-on-Register-to-Hotspot-SmartEndpoint-or-Global/m-p/72854#M1926</guid>
      <dc:creator>Daniel_Hainich</dc:creator>
      <dc:date>2020-01-21T14:05:31Z</dc:date>
    </item>
    <item>
      <title>Re: Enable any port on Register to Hotspot (SmartEndpoint or Global Properties)</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Enable-any-port-on-Register-to-Hotspot-SmartEndpoint-or-Global/m-p/72879#M1927</link>
      <description>This should be fixed in R80.40.&lt;BR /&gt;Haven't heard of they've backported this in earlier releases, but a TAC case is the way to find out.</description>
      <pubDate>Tue, 21 Jan 2020 16:21:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Enable-any-port-on-Register-to-Hotspot-SmartEndpoint-or-Global/m-p/72879#M1927</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-01-21T16:21:50Z</dc:date>
    </item>
    <item>
      <title>Re: Enable any port on Register to Hotspot (SmartEndpoint or Global Properties)</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Enable-any-port-on-Register-to-Hotspot-SmartEndpoint-or-Global/m-p/73009#M1932</link>
      <description>&lt;P&gt;1.) The &lt;STRONG&gt;port-range&lt;/STRONG&gt; doesn't work, as PhoneBoy mentioned it should be fixed in R80.40.&lt;/P&gt;&lt;P&gt;For us the solution was to use &lt;STRONG&gt;any&lt;/STRONG&gt; port. To get it working you need to add &lt;STRONG&gt;any&lt;/STRONG&gt; in the SmartEndpoint policy on the Hotspot Settings &lt;SPAN&gt;(Policy -&amp;gt; Allow hotspot registration). I have tested this solution and it is working fine.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cp.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4090i38FB6DDF80FE5AA4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="cp.jpg" alt="cp.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Although, if you check the &lt;U&gt;trac.config&lt;/U&gt; file on the client side, the ports that are configured for the hotspot are the ones that are defined in the Global Properties on the gateway (not the ones from SmartEndpoint). But, apparently they are not applied, the configuration from the SmartEndpoint is the one that is applied (in our case &lt;STRONG&gt;any&lt;/STRONG&gt; port).&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;trac.config&lt;/STRONG&gt;:&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&amp;lt;PARAM fw_hotspot_ports="22"&amp;gt;&amp;lt;/PARAM&amp;gt;&lt;BR /&gt;&amp;lt;PARAM fw_hotspot_ports="443"&amp;gt;&amp;lt;/PARAM&amp;gt;&lt;BR /&gt;&amp;lt;PARAM fw_hotspot_ports="80"&amp;gt;&amp;lt;/PARAM&amp;gt;&lt;BR /&gt;&amp;lt;PARAM fw_hotspot_ports="8080"&amp;gt;&amp;lt;/PARAM&amp;gt; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2.) Also, to answer the second question. It is enough to define the hotspot policy in the SmartEndpoint console.&amp;nbsp; You can have the option on the Global Properties checked or unchecked, it won't make any difference as long as you are using SmartEndpoint. I tested it both ways, and SmartEndpoint configuration overrides the Global Properties.&lt;/P&gt;&lt;P&gt;In fact, we got the response from TAC regarding this second question and they said it depends if you enforce the &lt;EM&gt;Endpoint Firewall policy&lt;/EM&gt; or the &lt;EM&gt;Desktop Policy from SmartConsole (&lt;/EM&gt;as per&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;sk105644&lt;/STRONG&gt;)&lt;/EM&gt;. But, I have tried both options and they don't affect the hotspot registration settings. For us it always remained the one configured in the SmartEndpoint (testing was conducted with re-creating the VPN sites).&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2020 14:20:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Enable-any-port-on-Register-to-Hotspot-SmartEndpoint-or-Global/m-p/73009#M1932</guid>
      <dc:creator>Hrvoje_Brlek</dc:creator>
      <dc:date>2020-01-22T14:20:36Z</dc:date>
    </item>
    <item>
      <title>Re: Enable any port on Register to Hotspot (SmartEndpoint or Global Properties)</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Enable-any-port-on-Register-to-Hotspot-SmartEndpoint-or-Global/m-p/73017#M1933</link>
      <description>&lt;P&gt;thanks for reply. i will test it shortly.&lt;/P&gt;&lt;P&gt;edit: i have tested this solution and it works. hotspot-registration is working now with any port. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jan 2020 09:33:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Enable-any-port-on-Register-to-Hotspot-SmartEndpoint-or-Global/m-p/73017#M1933</guid>
      <dc:creator>Daniel_Hainich</dc:creator>
      <dc:date>2020-01-24T09:33:48Z</dc:date>
    </item>
    <item>
      <title>Re: Enable any port on Register to Hotspot (SmartEndpoint or Global Properties)</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Enable-any-port-on-Register-to-Hotspot-SmartEndpoint-or-Global/m-p/105182#M2837</link>
      <description>&lt;P&gt;Off topic, but on the global properties, remote access, hotspot / wifi registration section, where have you found the LOG for tracking? I thought it would be automatically sent up to the management server however unable to find it in the LOGS. Does anybody know where this LOG tracking entry is?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2020 19:48:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Enable-any-port-on-Register-to-Hotspot-SmartEndpoint-or-Global/m-p/105182#M2837</guid>
      <dc:creator>514numbers</dc:creator>
      <dc:date>2020-12-11T19:48:25Z</dc:date>
    </item>
  </channel>
</rss>

