- CheckMates
- :
- Products
- :
- CloudMates Products
- :
- Cloud Network Security
- :
- Discussion
- :
- Re: Port Requirement - Management Server and Gatew...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Port Requirement - Management Server and Gateways
Hello,
What is the exact port requirement between a Management Server and the Gateways/Clusters.
My Mgmt Server and GWs are in different Networks so need to open ports for communication
Thanks
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Check Point has implied rules which usually allow communications between management and gateways.
sk115600 shows how to view the implied rules in order to see specific management <-> gateway firewall rules.
sk52421 includes all of the ports used by Check Point's software.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just have a look at @HeikoAnkenbrand really nice paintings.
R80-x-Ports-Used-for-Communication-by-Various-Check-Point
Wolfgang
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Check Point has implied rules which usually allow communications between management and gateways.
sk115600 shows how to view the implied rules in order to see specific management <-> gateway firewall rules.
sk52421 includes all of the ports used by Check Point's software.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just have a look at @HeikoAnkenbrand really nice paintings.
R80-x-Ports-Used-for-Communication-by-Various-Check-Point
Wolfgang
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, the implied rules for the control connections are using the main IP address of the gateway and management objects.
Wolfgang
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I am in same situation. i need to allow the traffic in my internal firewall, for this i need details of ports which needs to be open between mgmt server and the firewall.
if you have made the list, please share the list.
WR
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This question is definitely answered by the links provided in this thread (which I've marked as "Solutions").
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Pay close attention to the default implied rules in sk115600 and you must account for all the relevant IP addresses of your Check Point assets on the third party firewall.
The tcp 18209, 18210 and 18211 ports are important for automated SIC certificate renewal (and manual SIC trust establishment when relevant)
The automatic certificate renewal is done at 75% of the life of the 5 year SIC certificate life, if I remember correctly, so it's not an everyday port but every few years.