<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NMAP Shows Ports 5060 &amp;amp; 2000 Open in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/NMAP-Shows-Ports-5060-amp-2000-Open/m-p/186029#M31028</link>
    <description>&lt;P&gt;Would it still be applicable to 5600 appliances though?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Mon, 10 Jul 2023 13:57:39 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-07-10T13:57:39Z</dc:date>
    <item>
      <title>NMAP Shows Ports 5060 &amp; 2000 Open</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NMAP-Shows-Ports-5060-amp-2000-Open/m-p/186005#M31026</link>
      <description>&lt;P&gt;Hello Community,&lt;/P&gt;&lt;P&gt;Greetings to all.&lt;/P&gt;&lt;P&gt;Using the NMAP tool, I did a port scan in my internal network and found&amp;nbsp;ports 2000 and 5060 Open. Interestingly, NMAP found these ports open on security gateway Mgmt IPs and management server IP addresses. In the rule base, only ports 22 (SSH) and 443 (HTTPS) is allowed on Gateway and SMS IPs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Somehow, I can do telnet on 172.16.1.37 5060 and 172.16.1.37 2000. When I check the logs for these Telnet connections it shows "Drop" and hits the explicit rule I created.&lt;/P&gt;&lt;P&gt;The question is if ports 5060 and 2000 are not allowed in the security policy then why and how Telnet is possible despite the "DROP" log seen on the smart console?&lt;/P&gt;&lt;P&gt;Looking forward to suggestions.&lt;/P&gt;&lt;P&gt;Checkpoint 5600 HA (Active-Passive)&lt;/P&gt;&lt;P&gt;OS: GAIA R81.10 Take 87&lt;/P&gt;&lt;P&gt;Blades: IPS, Anti Virus, AntiBot&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;Digo.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 07:09:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NMAP-Shows-Ports-5060-amp-2000-Open/m-p/186005#M31026</guid>
      <dc:creator>Digo11</dc:creator>
      <dc:date>2023-07-10T07:09:06Z</dc:date>
    </item>
    <item>
      <title>Re: NMAP Shows Ports 5060 &amp; 2000 Open</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NMAP-Shows-Ports-5060-amp-2000-Open/m-p/186027#M31027</link>
      <description>&lt;P&gt;Looks like it is related to the issue mentioned in&amp;nbsp;sk177251:&lt;/P&gt;
&lt;P&gt;Quantum Spark appliance ports in built-in SIP services are opened for port-scan/Telnet without any allowing rule&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk177251" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk177251&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also found other cases that state these ports are open for VoIP purposes so check if your policy uses them.&lt;/P&gt;
&lt;P&gt;In any case I would contact TAC or a further assistance.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 13:27:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NMAP-Shows-Ports-5060-amp-2000-Open/m-p/186027#M31027</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2023-07-10T13:27:34Z</dc:date>
    </item>
    <item>
      <title>Re: NMAP Shows Ports 5060 &amp; 2000 Open</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NMAP-Shows-Ports-5060-amp-2000-Open/m-p/186029#M31028</link>
      <description>&lt;P&gt;Would it still be applicable to 5600 appliances though?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 13:57:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NMAP-Shows-Ports-5060-amp-2000-Open/m-p/186029#M31028</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-10T13:57:39Z</dc:date>
    </item>
    <item>
      <title>Re: NMAP Shows Ports 5060 &amp; 2000 Open</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NMAP-Shows-Ports-5060-amp-2000-Open/m-p/186082#M31032</link>
      <description>&lt;P&gt;Are there any rules involving SIP?&lt;BR /&gt;Might require a TAC case to investigate.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 22:36:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NMAP-Shows-Ports-5060-amp-2000-Open/m-p/186082#M31032</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-07-10T22:36:40Z</dc:date>
    </item>
    <item>
      <title>Re: NMAP Shows Ports 5060 &amp; 2000 Open</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NMAP-Shows-Ports-5060-amp-2000-Open/m-p/186170#M31055</link>
      <description>&lt;P&gt;No, we do not have any rules with SIP. It is a core firewall with no SIP traffic.&lt;/P&gt;&lt;P&gt;Thank you for the suggestion. I will involve TAC in this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Digo.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2023 02:18:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NMAP-Shows-Ports-5060-amp-2000-Open/m-p/186170#M31055</guid>
      <dc:creator>Digo11</dc:creator>
      <dc:date>2023-07-12T02:18:43Z</dc:date>
    </item>
  </channel>
</rss>

