- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
What's New in R82.10?
Register HereWhen the Agents Attack
A Live Look at Agentic Exposure Validation
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
Hello,
What is the exact port requirement between a Management Server and the Gateways/Clusters.
My Mgmt Server and GWs are in different Networks so need to open ports for communication
Thanks
Check Point has implied rules which usually allow communications between management and gateways.
sk115600 shows how to view the implied rules in order to see specific management <-> gateway firewall rules.
sk52421 includes all of the ports used by Check Point's software.
Just have a look at @HeikoAnkenbrand really nice paintings.
R80-x-Ports-Used-for-Communication-by-Various-Check-Point
Wolfgang
Check Point has implied rules which usually allow communications between management and gateways.
sk115600 shows how to view the implied rules in order to see specific management <-> gateway firewall rules.
sk52421 includes all of the ports used by Check Point's software.
Just have a look at @HeikoAnkenbrand really nice paintings.
R80-x-Ports-Used-for-Communication-by-Various-Check-Point
Wolfgang
Yes, the implied rules for the control connections are using the main IP address of the gateway and management objects.
Wolfgang
I am in same situation. i need to allow the traffic in my internal firewall, for this i need details of ports which needs to be open between mgmt server and the firewall.
if you have made the list, please share the list.
WR
This question is definitely answered by the links provided in this thread (which I've marked as "Solutions").
Pay close attention to the default implied rules in sk115600 and you must account for all the relevant IP addresses of your Check Point assets on the third party firewall.
The tcp 18209, 18210 and 18211 ports are important for automated SIC certificate renewal (and manual SIC trust establishment when relevant)
The automatic certificate renewal is done at 75% of the life of the 5 year SIC certificate life, if I remember correctly, so it's not an everyday port but every few years.
List of ports required communication between GW and Mgmt, FW1, CPD, FW1_log, CPMI, CPM, CP_rtm, CPD_amon,HTTPs, SSH
18191,18210, 18190,19009,18210,18211,18192,18209,443,257
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 3 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 16 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point SASE | Internet Access Optimization & Performance TuningThu 18 Jun 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point WAF - The Next Generation of AI powered protectionTue 23 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point Cloud Firewall | Securing all of your clouds: Art of the possibleTue 16 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point SASE | Internet Access Optimization & Performance TuningThu 18 Jun 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point WAF - The Next Generation of AI powered protectionTue 23 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point Cloud Firewall | Securing all of your clouds: Art of the possibleThu 25 Jun 2026 @ 10:00 AM (PDT)
AI Security Masters E10: READY OR NOT: Securing the AI Enterprise 2/5 - AI Red TeamingAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY