<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PCI Scan turns on ports dynamically in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/PCI-Scan-turns-on-ports-dynamically/m-p/35460#M7490</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Something like this?&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/63967_pastedImage_1.png" style="width: 903px; height: 185px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 19 Mar 2018 18:45:49 GMT</pubDate>
    <dc:creator>Vladimir</dc:creator>
    <dc:date>2018-03-19T18:45:49Z</dc:date>
    <item>
      <title>PCI Scan turns on ports dynamically</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PCI-Scan-turns-on-ports-dynamically/m-p/35455#M7485</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tenable Scan will dynamically open up various ports "SMTP Server Non-standard Port Detection" only on 2 out of the 16 gateways in our production environment. So far it has only happened&amp;nbsp;on the secondaries.&lt;/P&gt;&lt;P&gt;It does this everytime even after a fresh reboot of the gateway.&amp;nbsp;&lt;/P&gt;&lt;P&gt;All GW's are running R77.30 Jumbo 286.&amp;nbsp; Anyone ever heard of this.&amp;nbsp; We had a case opened a few months back but got no where. Any advice would be greatly appreciated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks -pat&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Mar 2018 19:19:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PCI-Scan-turns-on-ports-dynamically/m-p/35455#M7485</guid>
      <dc:creator>Patrick_Tuttle</dc:creator>
      <dc:date>2018-03-14T19:19:34Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Scan turns on ports dynamically</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PCI-Scan-turns-on-ports-dynamically/m-p/35456#M7486</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check Point gateways have userpsace processes that listen on random high ports.&lt;/P&gt;&lt;P&gt;The primary reason for this is to fold specific types of traffic into&amp;nbsp;the processes that perform different types of content inspection.&lt;/P&gt;&lt;P&gt;It's entirely possible that, if you haven't implemented a stealth rule in your rulebase properly, that something like a Tenable may pick up one of these random high ports.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Mar 2018 22:25:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PCI-Scan-turns-on-ports-dynamically/m-p/35456#M7486</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-03-16T22:25:34Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Scan turns on ports dynamically</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PCI-Scan-turns-on-ports-dynamically/m-p/35457#M7487</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks I appreciate the explanation and replies.&amp;nbsp; We would like to implement an over&amp;nbsp;scan rule / tighten up our stealth rule by not allowing any scans such as implementing SK110873 but so far We have been not successful in getting that change passed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks again&lt;/P&gt;&lt;P&gt;-pat&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Mar 2018 13:32:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PCI-Scan-turns-on-ports-dynamically/m-p/35457#M7487</guid>
      <dc:creator>Patrick_Tuttle</dc:creator>
      <dc:date>2018-03-19T13:32:05Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Scan turns on ports dynamically</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PCI-Scan-turns-on-ports-dynamically/m-p/35458#M7488</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dameon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How doe the stealth rule works in situations when GW has to be directly accessible by internal hosts, (i.e.&amp;nbsp;captive portal, user check portal, platform portal, etc.)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Mar 2018 17:20:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PCI-Scan-turns-on-ports-dynamically/m-p/35458#M7488</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-03-19T17:20:27Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Scan turns on ports dynamically</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PCI-Scan-turns-on-ports-dynamically/m-p/35459#M7489</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You would create the various required access rules prior to the Stealth Rule.&lt;/P&gt;&lt;P&gt;In fact, this may be a situation where a Policy Layer might be useful in R80.10+.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Mar 2018 18:03:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PCI-Scan-turns-on-ports-dynamically/m-p/35459#M7489</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-03-19T18:03:32Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Scan turns on ports dynamically</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PCI-Scan-turns-on-ports-dynamically/m-p/35460#M7490</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Something like this?&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/63967_pastedImage_1.png" style="width: 903px; height: 185px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Mar 2018 18:45:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PCI-Scan-turns-on-ports-dynamically/m-p/35460#M7490</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-03-19T18:45:49Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Scan turns on ports dynamically</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PCI-Scan-turns-on-ports-dynamically/m-p/35461#M7491</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah like that&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Mar 2018 20:11:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PCI-Scan-turns-on-ports-dynamically/m-p/35461#M7491</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-03-19T20:11:43Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Scan turns on ports dynamically</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PCI-Scan-turns-on-ports-dynamically/m-p/54776#M10944</link>
      <description>&lt;P&gt;Hi , I also had this particular findings after a nessus (tenable) scan. Di you already find out the solution to eliminate the findings? thank you very much&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.JPG" style="width: 831px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1420i4DF1B14255FE91A0/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.JPG" alt="Capture.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2019 02:24:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PCI-Scan-turns-on-ports-dynamically/m-p/54776#M10944</guid>
      <dc:creator>Richard_Anton_V</dc:creator>
      <dc:date>2019-05-31T02:24:20Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Scan turns on ports dynamically</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PCI-Scan-turns-on-ports-dynamically/m-p/65739#M13434</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Got the same behaviour on R80.20 gateway (with Management and gw on the same hardware). The question is why do they have those SMTP ports opened?&lt;/P&gt;&lt;P&gt;Even if&amp;nbsp; "The primary reason for this is to fold specific types of traffic into the processes that perform different types of content inspection." I don't understand why those ports are open.&lt;/P&gt;&lt;P&gt;Of course a Stealth Rules will mitigate the impact... but from a Security point of view, those are still open&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2019 07:42:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PCI-Scan-turns-on-ports-dynamically/m-p/65739#M13434</guid>
      <dc:creator>DR_74</dc:creator>
      <dc:date>2019-10-24T07:42:39Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Scan turns on ports dynamically</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PCI-Scan-turns-on-ports-dynamically/m-p/66021#M13500</link>
      <description>&lt;P&gt;Open port does not represent a security risk. The answer is already given: in case of content inspection, the traffic should be folded for inspection&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2019 07:51:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PCI-Scan-turns-on-ports-dynamically/m-p/66021#M13500</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2019-10-28T07:51:11Z</dc:date>
    </item>
  </channel>
</rss>

