<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Close Default Open Ports in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Close-Default-Open-Ports/m-p/71991#M14596</link>
    <description>&lt;P&gt;Thanks PhoneBoy, I think that did the trick.&lt;/P&gt;&lt;P&gt;SecurePlatform and UserCheck were both set to "internal_interfaces" but SmartView was set to "all_interfaces".&lt;/P&gt;&lt;P&gt;I set that to internal_interfaces, saved and installed policy.&lt;/P&gt;&lt;P&gt;The implied rule 0 accepts on 443 and 80 seem to have stopped, and now GRC Shields Up reports those ports as Stealth &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 10 Jan 2020 02:27:13 GMT</pubDate>
    <dc:creator>Lockout888</dc:creator>
    <dc:date>2020-01-10T02:27:13Z</dc:date>
    <item>
      <title>Close Default Open Ports</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Close-Default-Open-Ports/m-p/66845#M13707</link>
      <description>&lt;P&gt;I have a Cleanup Rule any/any to drop traffic from the Internet, but a Shields Up scan from grc.com shows I have several ports open by default:&amp;nbsp; 80, 264, 443 and 444.&lt;/P&gt;&lt;P&gt;What configuration changes do I need to "stealth" these ports?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ScreenShot715.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/3004i0B847440D40C150E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ScreenShot715.jpg" alt="ScreenShot715.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2019 07:48:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Close-Default-Open-Ports/m-p/66845#M13707</guid>
      <dc:creator>Lockout888</dc:creator>
      <dc:date>2019-11-08T07:48:02Z</dc:date>
    </item>
    <item>
      <title>Re: Close Default Open Ports</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Close-Default-Open-Ports/m-p/66944#M13730</link>
      <description>80/443 is Multiportal.&lt;BR /&gt;See: &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk105740" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk105740&lt;/A&gt;&lt;BR /&gt;Port 264 is related to a Remote Access implies rule, go to Global Properties &amp;gt; Firewall &amp;gt; Accept Remote Access Control Connections, uncheck this, and install policy.&lt;BR /&gt;Port 444 is not one of our standard ports and may be related to your specific configuration.</description>
      <pubDate>Sat, 09 Nov 2019 07:55:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Close-Default-Open-Ports/m-p/66944#M13730</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-11-09T07:55:06Z</dc:date>
    </item>
    <item>
      <title>Re: Close Default Open Ports</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Close-Default-Open-Ports/m-p/71986#M14593</link>
      <description>&lt;P&gt;I set the Platform Portal Accessibility settings to "Through internal interfaces" with no options checked per the SK solution.&amp;nbsp; I verified my Topology settings are correct (eth1 = external and Mgmt = Internal).&lt;/P&gt;&lt;P&gt;I am still getting implied Rule 0 accepts for 443 and 80 in the logs. This is a Standalone configuration if that matters.&lt;/P&gt;&lt;P&gt;The SK other solution says:&amp;nbsp; "In case you do not want to allow any connections to the Security Gateway's portals , add a rule that drop this traffic."&lt;/P&gt;&lt;P&gt;How do I add a rule that will drop the traffic of an implied rule?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2020 22:41:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Close-Default-Open-Ports/m-p/71986#M14593</guid>
      <dc:creator>Lockout888</dc:creator>
      <dc:date>2020-01-09T22:41:03Z</dc:date>
    </item>
    <item>
      <title>Re: Close Default Open Ports</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Close-Default-Open-Ports/m-p/71988#M14594</link>
      <description>See also: &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk155512" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk155512&lt;/A&gt;</description>
      <pubDate>Thu, 09 Jan 2020 23:00:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Close-Default-Open-Ports/m-p/71988#M14594</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-01-09T23:00:14Z</dc:date>
    </item>
    <item>
      <title>Re: Close Default Open Ports</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Close-Default-Open-Ports/m-p/71989#M14595</link>
      <description>&lt;P&gt;You can follow &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk115600" target="_self"&gt;sk115600&lt;/A&gt; to disable the implied rules. I would not recommend doing this however as you will have to create explicit rules to replace the implicit rules and this usually just leads to a lot of headaches.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2020 23:29:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Close-Default-Open-Ports/m-p/71989#M14595</guid>
      <dc:creator>KernelGordon</dc:creator>
      <dc:date>2020-01-09T23:29:49Z</dc:date>
    </item>
    <item>
      <title>Re: Close Default Open Ports</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Close-Default-Open-Ports/m-p/71991#M14596</link>
      <description>&lt;P&gt;Thanks PhoneBoy, I think that did the trick.&lt;/P&gt;&lt;P&gt;SecurePlatform and UserCheck were both set to "internal_interfaces" but SmartView was set to "all_interfaces".&lt;/P&gt;&lt;P&gt;I set that to internal_interfaces, saved and installed policy.&lt;/P&gt;&lt;P&gt;The implied rule 0 accepts on 443 and 80 seem to have stopped, and now GRC Shields Up reports those ports as Stealth &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2020 02:27:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Close-Default-Open-Ports/m-p/71991#M14596</guid>
      <dc:creator>Lockout888</dc:creator>
      <dc:date>2020-01-10T02:27:13Z</dc:date>
    </item>
  </channel>
</rss>

