<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Port Status Closed vs Port Status Filtered in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Port-Status-Closed-vs-Port-Status-Filtered/m-p/168591#M28049</link>
    <description>&lt;P&gt;I presume:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Closed: A TCP Reset or an ICMP Port Unreachable was received in response to a probe attempt. This generally means you've reached the target host, though it can happen for other reasons as well.&lt;/LI&gt;
&lt;LI&gt;Filtered: No response was received to a probe attempt. This generally means the traffic is being blocked by something along the way (i.e. a firewall), but can also happen for other reasons (routing issues).&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;To change from "Closed" to "Filtered" you would need to create the appropriate Access Policy rule to block the relevant traffic.&lt;/P&gt;</description>
    <pubDate>Fri, 20 Jan 2023 19:37:23 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-01-20T19:37:23Z</dc:date>
    <item>
      <title>Port Status Closed vs Port Status Filtered</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Port-Status-Closed-vs-Port-Status-Filtered/m-p/168541#M28034</link>
      <description>&lt;P&gt;We recently had a PT Scan run on our Checkpoint environment and it pointed out a few ports whose state is showing as CLOSED.&lt;/P&gt;&lt;P&gt;The recommendation from SOC was to change it to filtered mode..i.e in scan these should reflect as FILTERED in place of CLOSED.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My query is what does this actually mean ? how can this be configured to change it from CLOSED to FILTERED ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help is appreciated.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jan 2023 14:15:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Port-Status-Closed-vs-Port-Status-Filtered/m-p/168541#M28034</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2023-01-20T14:15:11Z</dc:date>
    </item>
    <item>
      <title>Re: Port Status Closed vs Port Status Filtered</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Port-Status-Closed-vs-Port-Status-Filtered/m-p/168591#M28049</link>
      <description>&lt;P&gt;I presume:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Closed: A TCP Reset or an ICMP Port Unreachable was received in response to a probe attempt. This generally means you've reached the target host, though it can happen for other reasons as well.&lt;/LI&gt;
&lt;LI&gt;Filtered: No response was received to a probe attempt. This generally means the traffic is being blocked by something along the way (i.e. a firewall), but can also happen for other reasons (routing issues).&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;To change from "Closed" to "Filtered" you would need to create the appropriate Access Policy rule to block the relevant traffic.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jan 2023 19:37:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Port-Status-Closed-vs-Port-Status-Filtered/m-p/168591#M28049</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-01-20T19:37:23Z</dc:date>
    </item>
    <item>
      <title>Re: Port Status Closed vs Port Status Filtered</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Port-Status-Closed-vs-Port-Status-Filtered/m-p/169390#M28162</link>
      <description>&lt;P&gt;what should be under "Action" for an access rule which should put a port in filtered mode ?&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 09:43:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Port-Status-Closed-vs-Port-Status-Filtered/m-p/169390#M28162</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2023-01-27T09:43:28Z</dc:date>
    </item>
    <item>
      <title>Re: Port Status Closed vs Port Status Filtered</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Port-Status-Closed-vs-Port-Status-Filtered/m-p/169391#M28163</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Block&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 09:52:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Port-Status-Closed-vs-Port-Status-Filtered/m-p/169391#M28163</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-01-27T09:52:10Z</dc:date>
    </item>
    <item>
      <title>Re: Port Status Closed vs Port Status Filtered</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Port-Status-Closed-vs-Port-Status-Filtered/m-p/169393#M28164</link>
      <description>&lt;P&gt;ok so a cleanup rule with any any any deny doesn't put a port in filtered mode..to put a port in filtered mode an explicit block rule is required ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 10:05:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Port-Status-Closed-vs-Port-Status-Filtered/m-p/169393#M28164</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2023-01-27T10:05:13Z</dc:date>
    </item>
    <item>
      <title>Re: Port Status Closed vs Port Status Filtered</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Port-Status-Closed-vs-Port-Status-Filtered/m-p/169447#M28168</link>
      <description>&lt;P&gt;What precise port on what precise device is being reported as Closed instead of Filtered?&lt;BR /&gt;The answer generally depends on what other access rules exist.&lt;BR /&gt;If the destination is a Check Point gateway, implied rules will also impact this.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 17:56:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Port-Status-Closed-vs-Port-Status-Filtered/m-p/169447#M28168</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-01-27T17:56:48Z</dc:date>
    </item>
    <item>
      <title>Re: Port Status Closed vs Port Status Filtered</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Port-Status-Closed-vs-Port-Status-Filtered/m-p/169459#M28170</link>
      <description>&lt;P&gt;Block and deny aren't actions in Check Point access rules. &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&amp;nbsp;The precise terminology matters here.&lt;/P&gt;
&lt;P&gt;In an access layer, the action Reject sends a RST in response to matching TCP connections, or an ICMP Destination Unreachable, Administratively Prohibited (type 3, code 13, I think) message in response to non-TCP traffic.&lt;/P&gt;
&lt;P&gt;In an access layer, the action Drop discards the traffic silently.&lt;/P&gt;
&lt;P&gt;I would argue with the SOC that it doesn't matter. Either result provides the same information back to a potential attacker: there is something there, and the traffic they tried isn't allowed. Hiding is not a valid strategy for network defense. Instead, set up a few canaries, and if anybody tries to access any of them, block the scanner for a day.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 20:54:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Port-Status-Closed-vs-Port-Status-Filtered/m-p/169459#M28170</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-01-27T20:54:49Z</dc:date>
    </item>
    <item>
      <title>Re: Port Status Closed vs Port Status Filtered</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Port-Status-Closed-vs-Port-Status-Filtered/m-p/169577#M28179</link>
      <description>&lt;P&gt;&lt;SPAN&gt;TCP/444/SNPP/CLOSED TCP/500/ISAKMP/CLOSED TCP/4500/SAE-URN/CLOSED TCP/8082/BLACKICE-ALERTS/CLOSED TCP/8880/CDDBP-ALT/CLOSED TCP/61447/UNKNOWN/CLOSED&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These are the mentioned ports but these are all for GW IP and there is already a stealth rule present.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2023 10:37:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Port-Status-Closed-vs-Port-Status-Filtered/m-p/169577#M28179</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2023-01-30T10:37:49Z</dc:date>
    </item>
    <item>
      <title>Re: Port Status Closed vs Port Status Filtered</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Port-Status-Closed-vs-Port-Status-Filtered/m-p/169614#M28180</link>
      <description>&lt;P&gt;Pretty sure the VPN ports there (500/4500) are being allowed through implied rules.&lt;BR /&gt;Same with port 444, which I believe is the legacy SNX portal.&lt;BR /&gt;If you have VPN enabled on your gateway those ports will be open.&lt;BR /&gt;We use various other random high ports for various security functions which may appear open.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2023 13:46:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Port-Status-Closed-vs-Port-Status-Filtered/m-p/169614#M28180</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-01-30T13:46:39Z</dc:date>
    </item>
    <item>
      <title>Re: Port Status Closed vs Port Status Filtered</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Port-Status-Closed-vs-Port-Status-Filtered/m-p/169632#M28184</link>
      <description>&lt;P&gt;The ones which are showing as CLOSED.. if i put an explicit rule for these ports with action "BLOCK" will they reflect as FILTERED ?&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2023 14:55:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Port-Status-Closed-vs-Port-Status-Filtered/m-p/169632#M28184</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2023-01-30T14:55:50Z</dc:date>
    </item>
    <item>
      <title>Re: Port Status Closed vs Port Status Filtered</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Port-Status-Closed-vs-Port-Status-Filtered/m-p/169633#M28185</link>
      <description>&lt;P&gt;Maybe TAC can help here much quicker ?&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2023 14:56:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Port-Status-Closed-vs-Port-Status-Filtered/m-p/169633#M28185</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-01-30T14:56:59Z</dc:date>
    </item>
    <item>
      <title>Re: Port Status Closed vs Port Status Filtered</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Port-Status-Closed-vs-Port-Status-Filtered/m-p/169667#M28197</link>
      <description>&lt;P&gt;Not if they're being allowed through implied rules, which the VPN ones are.&lt;BR /&gt;Not sure about the others, but an explicit "stealth rule" for the Security Gateway/Cluster is considered best practice.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2023 20:01:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Port-Status-Closed-vs-Port-Status-Filtered/m-p/169667#M28197</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-01-30T20:01:55Z</dc:date>
    </item>
    <item>
      <title>Re: Port Status Closed vs Port Status Filtered</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Port-Status-Closed-vs-Port-Status-Filtered/m-p/169875#M28241</link>
      <description>&lt;P&gt;Contacted TAC and they are saying there is not way to put a port in Filtered mode which is quite surprising.&lt;/P&gt;&lt;P&gt;I guess nothing can be done in that case.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 09:18:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Port-Status-Closed-vs-Port-Status-Filtered/m-p/169875#M28241</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2023-02-01T09:18:37Z</dc:date>
    </item>
    <item>
      <title>Re: Port Status Closed vs Port Status Filtered</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Port-Status-Closed-vs-Port-Status-Filtered/m-p/169898#M28248</link>
      <description>&lt;TABLE id="filterportTable" border="1" width="100%" cellspacing="2" cellpadding="4"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style="text-align: center; width: 10%;"&gt;TCP&lt;/TD&gt;
&lt;TD style="text-align: center; width: 10%;"&gt;444&lt;/TD&gt;
&lt;TD style="width: 30%;"&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/TD&gt;
&lt;TD style="width: 50%;"&gt;Required port for Remote Access client Site Creation&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE id="filterportTable" border="1" width="100%" cellspacing="2" cellpadding="4"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style="text-align: center; width: 10%;"&gt;TCP&lt;/TD&gt;
&lt;TD style="text-align: center; width: 10%;"&gt;500&lt;/TD&gt;
&lt;TD style="width: 30%;"&gt;&lt;EM&gt;IKE_tcp&lt;/EM&gt;&amp;nbsp;- IPSEC Internet Key Exchange Protocol over TCP&lt;/TD&gt;
&lt;TD style="width: 50%;"&gt;IKE negotiation over TCP (by VPND daemon)&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE id="filterportTable" border="1" width="100%" cellspacing="2" cellpadding="4"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="10%" style="text-align: center; width: 10%;"&gt;TCP&amp;nbsp;&lt;/TD&gt;
&lt;TD width="10%" style="text-align: center; width: 10%;"&gt;4500&lt;/TD&gt;
&lt;TD width="30%" style="width: 30%;"&gt;&lt;EM&gt;not predefined&amp;nbsp;&lt;/EM&gt;&lt;/TD&gt;
&lt;TD width="50%" style="width: 50%;"&gt;relevant for cases where TCP encapsulation is used for RA VPN traffic&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE id="filterportTable" border="1" width="100%" cellspacing="2" cellpadding="4"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style="text-align: center; width: 10%;"&gt;TCP&lt;/TD&gt;
&lt;TD style="text-align: center; width: 10%;"&gt;8082&lt;/TD&gt;
&lt;TD style="width: 30%;"&gt;&lt;EM&gt;not predefined&amp;nbsp;&lt;/EM&gt;&lt;/TD&gt;
&lt;TD style="width: 50%;"&gt;Internal&amp;nbsp;SmartView port&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE id="filterportTable" border="1" width="100%" cellspacing="2" cellpadding="4"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style="text-align: center; width: 10%;"&gt;TCP&amp;nbsp;&lt;/TD&gt;
&lt;TD style="text-align: center; width: 10%;"&gt;8880&lt;/TD&gt;
&lt;TD style="width: 30%;"&gt;&lt;EM&gt;not predefined&amp;nbsp;&lt;/EM&gt;&lt;/TD&gt;
&lt;TD style="width: 50%;"&gt;Security Gateway listens on this port for communication with Mobile Access.&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From: &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk52421&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk52421&amp;amp;partition=Advanced&amp;amp;product=Quantum&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 11:59:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Port-Status-Closed-vs-Port-Status-Filtered/m-p/169898#M28248</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-02-01T11:59:47Z</dc:date>
    </item>
  </channel>
</rss>

