<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SMB listening on HTTPS in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-listening-on-HTTPS/m-p/278224#M13988</link>
    <description>&lt;P&gt;Thanks, I believe it's the answer. The article is a little confusing to me and lacks some info.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't find those same settings on the SMB firewalls.&lt;/P&gt;&lt;P&gt;Thanks for the link though.&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jun 2026 11:48:19 GMT</pubDate>
    <dc:creator>velo</dc:creator>
    <dc:date>2026-06-10T11:48:19Z</dc:date>
    <item>
      <title>SMB listening on HTTPS</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-listening-on-HTTPS/m-p/278102#M13975</link>
      <description>&lt;P&gt;Morning&lt;/P&gt;&lt;P&gt;We have an estate of SMB appliances that are centrally managed. During pen tests it has been picked up that they are listening on HTTPS (443). I raised this with TAC and they have said this is normal, and related to management, or VPN. This doesn't seem right to me? Gaia management is on 4434.&lt;/P&gt;&lt;P&gt;Does anybody have any insight into this? If I do a tcpdump the firewalls get scanned on that port from externally (which is expected on the internet) The problem is this is generating unwanted traffic. How can I close this port?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2026 08:09:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-listening-on-HTTPS/m-p/278102#M13975</guid>
      <dc:creator>velo</dc:creator>
      <dc:date>2026-06-09T08:09:19Z</dc:date>
    </item>
    <item>
      <title>Re: SMB listening on HTTPS</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-listening-on-HTTPS/m-p/278107#M13976</link>
      <description>&lt;P&gt;Please review sk105740 it may be useful for you.&lt;/P&gt;
&lt;P&gt;If it is indeed RA-VPN related their is an option to instead reserve 443 for port-forwarding / NAT this is an advanced setting at least on locally-managed appliances.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2026 12:21:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-listening-on-HTTPS/m-p/278107#M13976</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2026-06-09T12:21:55Z</dc:date>
    </item>
    <item>
      <title>Re: SMB listening on HTTPS</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-listening-on-HTTPS/m-p/278224#M13988</link>
      <description>&lt;P&gt;Thanks, I believe it's the answer. The article is a little confusing to me and lacks some info.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't find those same settings on the SMB firewalls.&lt;/P&gt;&lt;P&gt;Thanks for the link though.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2026 11:48:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-listening-on-HTTPS/m-p/278224#M13988</guid>
      <dc:creator>velo</dc:creator>
      <dc:date>2026-06-10T11:48:19Z</dc:date>
    </item>
  </channel>
</rss>

