<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Implied rules in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Implied-rules/m-p/12544#M2015</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As far as I know, NAT-T + Remote Access VPN&lt;BR /&gt;&lt;BR /&gt;However, if you have a concern about implied rules and handling of this traffic, please open a support case with TAC so we could investigate&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 04 Dec 2018 11:34:32 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2018-12-04T11:34:32Z</dc:date>
    <item>
      <title>Implied rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-rules/m-p/12534#M2005</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm looking for some help with the following, at the moment I see lots of external traffic being allowed by an implied rule on port TCP 4500. On smartview tracker the only info I have is the source external IP to our external firewalls over Port TCP 4500, which I'm not sure what service is using this port. My first thought was VPN, but my understanding is that the IKE uses port udp or tcp 500 and NAT-T port udp 4500.&lt;/P&gt;&lt;P&gt;There is no indication what would be allowing this traffic, as the only info I have is Accept 0-Implied rules. I just double checked the implied rules but cannot see anything allowing port TCP 4500 (screenshot attached).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you provide some guidance please?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Dec 2018 10:11:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-rules/m-p/12534#M2005</guid>
      <dc:creator>Reinaldo_Fernan</dc:creator>
      <dc:date>2018-12-04T10:11:14Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-rules/m-p/12535#M2006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk52421&amp;amp;partition=Advanced&amp;amp;product=All&amp;quot;"&gt;sk52421: &lt;STRONG&gt;Ports&lt;/STRONG&gt; used by Check Point software&lt;/A&gt;&amp;nbsp;:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="1" cellpadding="4" cellspacing="2" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;UDP&lt;/TD&gt;&lt;TD&gt;4500&lt;/TD&gt;&lt;TD&gt;&lt;EM&gt;IKE_NAT_TRAVERSAL&lt;/EM&gt;&amp;nbsp;- NAT Traversal (NAT-T) Protocol&lt;/TD&gt;&lt;TD&gt;NAT Traversal adds a UDP header, which encapsulates the IPSec ESP header (by VPND daemon).&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;And:&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk62692&amp;amp;partition=General&amp;amp;product=Endpoint"&gt;sk62692: Ports used on Security Gateway for SecureClient and Endpoint Security VPN&lt;/A&gt;&amp;nbsp;:&lt;/P&gt;&lt;P&gt;UDP 4500 - NAT-T port for industry standard UDP encapsulation&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Dec 2018 10:51:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-rules/m-p/12535#M2006</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-12-04T10:51:22Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-rules/m-p/12536#M2007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your prompt answer.&lt;/P&gt;&lt;P&gt;That is port UDP 4500, the behavior we are seeing is on port TCP 4500.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Dec 2018 10:54:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-rules/m-p/12536#M2007</guid>
      <dc:creator>Reinaldo_Fernan</dc:creator>
      <dc:date>2018-12-04T10:54:20Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-rules/m-p/12537#M2008</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;CP does not use that, so i think that there is no implied rule for it...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Dec 2018 10:56:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-rules/m-p/12537#M2008</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-12-04T10:56:54Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-rules/m-p/12538#M2009</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, I understand and I thought exactly the same...but if you see the screenshot that I attached that is not what it looks like.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Dec 2018 11:00:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-rules/m-p/12538#M2009</guid>
      <dc:creator>Reinaldo_Fernan</dc:creator>
      <dc:date>2018-12-04T11:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-rules/m-p/12539#M2010</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check RFC 8229&lt;/P&gt;&lt;P&gt;&lt;A href="https://tools.ietf.org/html/rfc8229"&gt;https://tools.ietf.org/html/rfc8229&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Dec 2018 11:11:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-rules/m-p/12539#M2010</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2018-12-04T11:11:46Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-rules/m-p/12540#M2011</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;TCP 4500 is used for TCP Encapsulation and is related to Remote Access VPN functionality.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Dec 2018 11:20:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-rules/m-p/12540#M2011</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-12-04T11:20:18Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-rules/m-p/12541#M2012</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your prompt answer.&lt;/P&gt;&lt;P&gt;I checked that document previously. Question is about implied rules, and we don't seem to have any implied rule to allow traffic on port TCP 4500 but we can see external IPs scanning our network and traffic over that port is being allowed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Dec 2018 11:21:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-rules/m-p/12541#M2012</guid>
      <dc:creator>Reinaldo_Fernan</dc:creator>
      <dc:date>2018-12-04T11:21:25Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-rules/m-p/12542#M2013</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your prompt reply.&lt;/P&gt;&lt;P&gt;Can you please tell me what it is supposed to see on the comment for this implied rule? or what is the service or destination?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Dec 2018 11:23:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-rules/m-p/12542#M2013</guid>
      <dc:creator>Reinaldo_Fernan</dc:creator>
      <dc:date>2018-12-04T11:23:29Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-rules/m-p/12543#M2014</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;and what option exactly&amp;nbsp; enables this functionality?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Dec 2018 11:25:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-rules/m-p/12543#M2014</guid>
      <dc:creator>Reinaldo_Fernan</dc:creator>
      <dc:date>2018-12-04T11:25:45Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-rules/m-p/12544#M2015</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As far as I know, NAT-T + Remote Access VPN&lt;BR /&gt;&lt;BR /&gt;However, if you have a concern about implied rules and handling of this traffic, please open a support case with TAC so we could investigate&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Dec 2018 11:34:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-rules/m-p/12544#M2015</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-12-04T11:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-rules/m-p/12545#M2016</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Valeri.&lt;/P&gt;&lt;P&gt;Not familiar with open TAC cases. Can you please give me some guidance how to do this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Dec 2018 11:46:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-rules/m-p/12545#M2016</guid>
      <dc:creator>Reinaldo_Fernan</dc:creator>
      <dc:date>2018-12-04T11:46:37Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-rules/m-p/12546#M2017</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I mean, open a support case with your support partner or Check Point directly, according to your maintenance contract.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk31559" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk31559"&gt;How to open a Service Request (SR)&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Dec 2018 12:42:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-rules/m-p/12546#M2017</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-12-04T12:42:53Z</dc:date>
    </item>
  </channel>
</rss>

