<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Local certificate shown on public IP in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Local-certificate-shown-on-public-IP/m-p/232713#M38868</link>
    <description>&lt;P&gt;That is an interesting read, thanks. I does not apply to our situation though, as the certificate in question gets shown on Port 443. We don't get anything here when trying for the ICA Ports...&lt;/P&gt;</description>
    <pubDate>Thu, 14 Nov 2024 12:52:19 GMT</pubDate>
    <dc:creator>Kryten</dc:creator>
    <dc:date>2024-11-14T12:52:19Z</dc:date>
    <item>
      <title>Local certificate shown on public IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Local-certificate-shown-on-public-IP/m-p/232686#M38865</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;a customer of ours recently had a PenTest done. All went pretty well but one of the findings was a not-so-secure RSA lenght with a certificate on a public IP.&lt;/P&gt;&lt;P&gt;The IP in question is the main IP of the Check Point Cluster and the certificate shown is the local VPN certificate.&lt;/P&gt;&lt;P&gt;The strange thing: This customer does not have the Mobile Access Blade enabled, so is not using SSL-VPN or any Portal that would run on this IP. Also we found nothing else that would explain why we can do a TLS Handshake to this IP. Its also just the Handshake, as there is no connection after accepting the cert.&lt;BR /&gt;While searching we found that Usercheck was pointing to this IP, but that was the only thing we found (and changed to an internal IP of the cluster).&lt;/P&gt;&lt;P&gt;If there is no portal or other service offered by the Gateway on this IP address, why can a connection on Port 443 still be initiated? Is there a way to disable this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers, and thanks in advance for any hints!&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 08:17:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Local-certificate-shown-on-public-IP/m-p/232686#M38865</guid>
      <dc:creator>Kryten</dc:creator>
      <dc:date>2024-11-14T08:17:39Z</dc:date>
    </item>
    <item>
      <title>Re: Local certificate shown on public IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Local-certificate-shown-on-public-IP/m-p/232688#M38866</link>
      <description>&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/HowTo-React-on-Check-Point-Information-Disclosure/td-p/9773" target="_blank" rel="noopener"&gt;HowTo: React on Check Point Information Disclosure&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 08:24:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Local-certificate-shown-on-public-IP/m-p/232688#M38866</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2024-11-14T08:24:31Z</dc:date>
    </item>
    <item>
      <title>Re: Local certificate shown on public IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Local-certificate-shown-on-public-IP/m-p/232713#M38868</link>
      <description>&lt;P&gt;That is an interesting read, thanks. I does not apply to our situation though, as the certificate in question gets shown on Port 443. We don't get anything here when trying for the ICA Ports...&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 12:52:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Local-certificate-shown-on-public-IP/m-p/232713#M38868</guid>
      <dc:creator>Kryten</dc:creator>
      <dc:date>2024-11-14T12:52:19Z</dc:date>
    </item>
    <item>
      <title>Re: Local certificate shown on public IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Local-certificate-shown-on-public-IP/m-p/232832#M38898</link>
      <description>&lt;P&gt;Can you edit the gateway, platform portal, accessibility and change it to internal or policy and see if that closes the port?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;also run "&lt;SPAN&gt;mpclient list" and see what services are running on 443&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 23:16:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Local-certificate-shown-on-public-IP/m-p/232832#M38898</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2024-11-14T23:16:39Z</dc:date>
    </item>
    <item>
      <title>Re: Local certificate shown on public IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Local-certificate-shown-on-public-IP/m-p/232889#M38904</link>
      <description>&lt;P&gt;You should probably adjust the implied rules that allow connectivity on port 443:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk105740" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk105740&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2024 13:57:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Local-certificate-shown-on-public-IP/m-p/232889#M38904</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-11-15T13:57:37Z</dc:date>
    </item>
  </channel>
</rss>

