<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Blocking ports 39960-40000 in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-ports-39960-40000/m-p/205163#M4077</link>
    <description>&lt;P&gt;Yes, we completely disable the mobile access blade, enable the rule for direct access from the network under test to the internal network, and set the policy. After that, everything starts working and we can hear voice in both directions.&lt;/P&gt;</description>
    <pubDate>Tue, 06 Feb 2024 13:13:24 GMT</pubDate>
    <dc:creator>Railx</dc:creator>
    <dc:date>2024-02-06T13:13:24Z</dc:date>
    <item>
      <title>Blocking ports 39960-40000</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-ports-39960-40000/m-p/205129#M4070</link>
      <description>&lt;P&gt;Good afternoon.&lt;/P&gt;&lt;P&gt;We use SIP telephony via Mobile Access. Users connect to Capsule VPN and can use the mobile app to make calls to our internal numbers.&lt;/P&gt;&lt;P&gt;Ports 10000-20000 are used for this purpose.&lt;/P&gt;&lt;P&gt;Now we have a need to introduce additional telephony, which will work on ports 39960-40000.&lt;BR /&gt;And there was a problem with that.&lt;BR /&gt;The call goes through, the call is set, but the voice is not heard.&lt;/P&gt;&lt;P&gt;All necessary ports on the gateways are open.&lt;/P&gt;&lt;P&gt;Here are the results of our tests:&lt;BR /&gt;1) SIP telephony works, which worked for us all the time at 10000-20000, does not work correctly on ports 399600-40000. The problem is the same, I can't hear the voice.&lt;/P&gt;&lt;P&gt;2) The new telephony has been switched to ports 10000-20000, everything works correctly, the call is set, the voice is heard.&lt;/P&gt;&lt;P&gt;3) We turned off the Capsule VPN for testing. Both SIP telephony and the new telephony work correctly on 10000-20000 and 399600-40000 ports.&lt;/P&gt;&lt;P&gt;Therefore, we conclude that Capsule VPN blocks ports 399600-40000, but we do not understand exactly how.&lt;BR /&gt;Please help me with this, maybe someone has already met with this.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 09:25:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-ports-39960-40000/m-p/205129#M4070</guid>
      <dc:creator>Railx</dc:creator>
      <dc:date>2024-02-06T09:25:23Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking ports 39960-40000</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-ports-39960-40000/m-p/205136#M4071</link>
      <description>&lt;P&gt;Ask CP TAC to resolve this !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 10:48:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-ports-39960-40000/m-p/205136#M4071</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-02-06T10:48:07Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking ports 39960-40000</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-ports-39960-40000/m-p/205139#M4072</link>
      <description>&lt;P&gt;Is this a different telephony vendor, how did you define the services compared to the previous ones and are back connections already enabled in global properties?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 11:31:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-ports-39960-40000/m-p/205139#M4072</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-02-06T11:31:36Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking ports 39960-40000</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-ports-39960-40000/m-p/205151#M4073</link>
      <description>&lt;P&gt;We used the old telephony on these ports for telephony only.&lt;BR /&gt;What we are most interested in is why everything works fine when Capsule VPN is turned off. But as soon as we enable the VPN, the connection is established, voice UDP (RTP) packets are sent from the server side to the user side, but no voice is heard. We don't get any return voice packets either.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 12:14:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-ports-39960-40000/m-p/205151#M4073</guid>
      <dc:creator>Railx</dc:creator>
      <dc:date>2024-02-06T12:14:46Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking ports 39960-40000</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-ports-39960-40000/m-p/205154#M4074</link>
      <description>&lt;P&gt;Wait...when you say you tested with turning off capsule VPN and it worked, what do you mean exactly by that? Capsule VPN is not blade itself, rather the app on the phone.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 12:21:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-ports-39960-40000/m-p/205154#M4074</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-06T12:21:46Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking ports 39960-40000</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-ports-39960-40000/m-p/205155#M4075</link>
      <description>&lt;P&gt;I apologize, yes you are right, I misspoke. We shut down MAB and checked.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 12:26:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-ports-39960-40000/m-p/205155#M4075</guid>
      <dc:creator>Railx</dc:creator>
      <dc:date>2024-02-06T12:26:29Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking ports 39960-40000</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-ports-39960-40000/m-p/205161#M4076</link>
      <description>&lt;P&gt;No worries. Just to be 100% sure we are on the same page here, so you turned off mobile access blade on the fw, installed policy and then all worked fine?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 12:56:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-ports-39960-40000/m-p/205161#M4076</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-06T12:56:18Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking ports 39960-40000</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-ports-39960-40000/m-p/205163#M4077</link>
      <description>&lt;P&gt;Yes, we completely disable the mobile access blade, enable the rule for direct access from the network under test to the internal network, and set the policy. After that, everything starts working and we can hear voice in both directions.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 13:13:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-ports-39960-40000/m-p/205163#M4077</guid>
      <dc:creator>Railx</dc:creator>
      <dc:date>2024-02-06T13:13:24Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking ports 39960-40000</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-ports-39960-40000/m-p/205170#M4078</link>
      <description>&lt;P&gt;You can try this...say port is 40000, run from expert -&amp;gt; fw ctl zdebug + drop | grep "40000"&lt;/P&gt;
&lt;P&gt;this is when mobile access blade is enabled&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 14:52:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-ports-39960-40000/m-p/205170#M4078</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-06T14:52:30Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking ports 39960-40000</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-ports-39960-40000/m-p/205217#M4079</link>
      <description>&lt;P&gt;Version/JHF of gateway?&lt;BR /&gt;Version of Capsule client?&lt;BR /&gt;What precise rules are being used to permit the traffic?&lt;BR /&gt;Please provide screenshots (sensitive details redacted)&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 19:24:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Blocking-ports-39960-40000/m-p/205217#M4079</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-02-06T19:24:24Z</dc:date>
    </item>
  </channel>
</rss>

