<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disabling all traces of SSL VPN portal in Mobile</title>
    <link>https://community.checkpoint.com/t5/Mobile/Disabling-all-traces-of-SSL-VPN-portal/m-p/240305#M1248</link>
    <description>&lt;P&gt;Is mobile access blade enabled?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Mon, 03 Feb 2025 17:46:33 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-02-03T17:46:33Z</dc:date>
    <item>
      <title>Disabling all traces of SSL VPN portal</title>
      <link>https://community.checkpoint.com/t5/Mobile/Disabling-all-traces-of-SSL-VPN-portal/m-p/240303#M1247</link>
      <description>&lt;P&gt;Hey guys.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Question.&lt;/P&gt;
&lt;P&gt;We are going to undergo an external vuln scan &amp;amp; pen test in the next month and I'd like to make sure my gateway is as "clean" as can be.&lt;/P&gt;
&lt;P&gt;I've recently turned off the SSL VPN&amp;nbsp; portal by simply unticking the options under "VPN Clients" (Other) and Mobile Access (Web).&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are only using the Check Point Mobile IPsec client.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So now in my testing when I go to &lt;A href="https://ipaddressof" target="_blank"&gt;https://ipaddress of gateway&lt;/A&gt;/sslvpn or /admin or /dlp, I receive an error page that basically says:&lt;/P&gt;
&lt;P&gt;Error (in red) - the service is no longer offered...With my old SSL VPN site banner on top of the page.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No big deal I suppose but I'd like the user to just receive a "Not Found" page.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I found the option under "Mobile Access"&amp;nbsp; / "Portal Settings" that allows you to specify how the portal is accessible:&lt;/P&gt;
&lt;P&gt;"Accessibility" / "The portal is accessible only through internal interfaces" - changed from "Through all interfaces"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once I specify that the portal is only accessible through internal interfaces, now in my testing I see a "Not Found" page.&lt;/P&gt;
&lt;P&gt;Of course this does not solve the issue if someone does an internal scan, then they'll see that error page again - again, not sure If I'm making a bigger deal out of this than is warranted.&amp;nbsp; There is no input allowed on the warning page.&amp;nbsp; There are no services offered in the portal.&lt;/P&gt;
&lt;P&gt;FYI - I tried creating a SAM rule that blocks all external traffic to port 443 on the gateway but that broke my ability to create sites to the gateway via my Check Point Mobile client.&amp;nbsp; Existing sites worked fine - I just could not create new sites until the SAM rule was disabled.&lt;/P&gt;
&lt;P&gt;Thoughts?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2025 16:58:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Mobile/Disabling-all-traces-of-SSL-VPN-portal/m-p/240303#M1247</guid>
      <dc:creator>Joe_Kanaszka</dc:creator>
      <dc:date>2025-02-03T16:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling all traces of SSL VPN portal</title>
      <link>https://community.checkpoint.com/t5/Mobile/Disabling-all-traces-of-SSL-VPN-portal/m-p/240305#M1248</link>
      <description>&lt;P&gt;Is mobile access blade enabled?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2025 17:46:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Mobile/Disabling-all-traces-of-SSL-VPN-portal/m-p/240305#M1248</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-03T17:46:33Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling all traces of SSL VPN portal</title>
      <link>https://community.checkpoint.com/t5/Mobile/Disabling-all-traces-of-SSL-VPN-portal/m-p/240309#M1249</link>
      <description>&lt;P&gt;Afternoon Andy!&amp;nbsp; Apologies for the late response.&amp;nbsp; Yes.&amp;nbsp; We need it for Check Point Mobile client VPN access for WFH.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2025 20:03:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Mobile/Disabling-all-traces-of-SSL-VPN-portal/m-p/240309#M1249</guid>
      <dc:creator>Joe_Kanaszka</dc:creator>
      <dc:date>2025-02-03T20:03:12Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling all traces of SSL VPN portal</title>
      <link>https://community.checkpoint.com/t5/Mobile/Disabling-all-traces-of-SSL-VPN-portal/m-p/240311#M1250</link>
      <description>&lt;P&gt;What does below look like?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29509i81738813536B6571/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2025 20:37:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Mobile/Disabling-all-traces-of-SSL-VPN-portal/m-p/240311#M1250</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-03T20:37:34Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling all traces of SSL VPN portal</title>
      <link>https://community.checkpoint.com/t5/Mobile/Disabling-all-traces-of-SSL-VPN-portal/m-p/240313#M1251</link>
      <description>&lt;P&gt;Just "Desktops / Laptops" is checked.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2025 20:41:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Mobile/Disabling-all-traces-of-SSL-VPN-portal/m-p/240313#M1251</guid>
      <dc:creator>Joe_Kanaszka</dc:creator>
      <dc:date>2025-02-03T20:41:46Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling all traces of SSL VPN portal</title>
      <link>https://community.checkpoint.com/t5/Mobile/Disabling-all-traces-of-SSL-VPN-portal/m-p/240314#M1252</link>
      <description>&lt;P&gt;Is SNX greyed out but checked or is it unchecked?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2025 20:52:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Mobile/Disabling-all-traces-of-SSL-VPN-portal/m-p/240314#M1252</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-03T20:52:55Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling all traces of SSL VPN portal</title>
      <link>https://community.checkpoint.com/t5/Mobile/Disabling-all-traces-of-SSL-VPN-portal/m-p/240316#M1253</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-02-03 160644.jpg" style="width: 752px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29511i23EBD511F48FFEBC/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2025-02-03 160644.jpg" alt="Screenshot 2025-02-03 160644.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unchecked&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2025 21:07:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Mobile/Disabling-all-traces-of-SSL-VPN-portal/m-p/240316#M1253</guid>
      <dc:creator>Joe_Kanaszka</dc:creator>
      <dc:date>2025-02-03T21:07:11Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling all traces of SSL VPN portal</title>
      <link>https://community.checkpoint.com/t5/Mobile/Disabling-all-traces-of-SSL-VPN-portal/m-p/240319#M1254</link>
      <description>&lt;P&gt;There was recent post about this where someone else asked very similar question. I believe&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;responded saying that MAB had to be unchecked for this to work properly, but I could be mistaken. let me see if I can find the link.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2025 21:46:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Mobile/Disabling-all-traces-of-SSL-VPN-portal/m-p/240319#M1254</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-03T21:46:52Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling all traces of SSL VPN portal</title>
      <link>https://community.checkpoint.com/t5/Mobile/Disabling-all-traces-of-SSL-VPN-portal/m-p/240323#M1255</link>
      <description>&lt;P&gt;Yes, the VPN client uses TCP Port 443 for creating the new site as well as Visitor Mode.&lt;BR /&gt;Blocking that port externally prevents these things from working.&lt;/P&gt;
&lt;P&gt;What's answering the query is Multiportal where /sslvpn is redirected to the relevant web server for Mobile Access (if it is enabled).&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2025 03:12:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Mobile/Disabling-all-traces-of-SSL-VPN-portal/m-p/240323#M1255</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-02-04T03:12:47Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling all traces of SSL VPN portal</title>
      <link>https://community.checkpoint.com/t5/Mobile/Disabling-all-traces-of-SSL-VPN-portal/m-p/262031#M1311</link>
      <description>&lt;P&gt;Hi, we have a scenario very similar than this but explicit rules are not working yet. We have blocking rules for traffic coming and going to certain countries, but logs says that connections are accepted from one of those forbidden countries and accepted by a Implicit Rule.&lt;/P&gt;&lt;P&gt;I viewed on the Global Properties and I saw that all control connection are enabled. Does one of those rules may be the reason of this?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Nov 2025 16:48:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Mobile/Disabling-all-traces-of-SSL-VPN-portal/m-p/262031#M1311</guid>
      <dc:creator>emacias-pronet</dc:creator>
      <dc:date>2025-11-06T16:48:16Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling all traces of SSL VPN portal</title>
      <link>https://community.checkpoint.com/t5/Mobile/Disabling-all-traces-of-SSL-VPN-portal/m-p/262075#M1312</link>
      <description>&lt;P&gt;It's an Implied Rule accepting this traffic, yes.&lt;BR /&gt;If you want to do county-specific blocking of this traffic, see:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Block-VPN-Traffic-by-Country/m-p/172695#M31396" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Block-VPN-Traffic-by-Country/m-p/172695#M31396&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Nov 2025 21:14:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Mobile/Disabling-all-traces-of-SSL-VPN-portal/m-p/262075#M1312</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-11-06T21:14:24Z</dc:date>
    </item>
  </channel>
</rss>

