- Products
- Learn
- Local User Groups
- Partners
- More
Check Point Jump-Start Online Training
Now Available on CheckMates for Beginners!
Why do Hackers Love IoT Devices so Much?
Join our TechTalk on Aug 17, at 5PM CET | 11AM EST
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
ZTNA Buyer’s Guide
Zero Trust essentials for your most valuable assets
The SMB Cyber Master
Boost your knowledge on Quantum Spark SMB gateways!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Hi all,
we are running R80.30 and we noticed that when we ping the mgmt. interface of the firewall, even though it is not enabled, it responds to ping.
We performed fw monitor -e "host(mgmt_ip),accept;" and run a continuous ping. The request passes the IN interface (iI) and then exits again through the same interface (oO) as expected.
We would have thought that because the mgmt. interface is not enabled, we shouldn't get a response.
Can someone explain this behavior?
Thank you in advance,
Katerina
Hi,
If you run a ping directly from the firewall to the mgmt intf when it's in off state, it's normal to respond to ping because locally it doesn't care about the state of the interface, unlike other vendors. From an external device the ping won't/shouldn't work.
How was the interface disabled and what was the source of the ping?
When you say the Mgmt interface note the 'role' can be assigned to another port on the appliance...
By saying "disabled", we see through GAIA that the port is not enabled and it has no physical connection to the rest of the infrastructure.
Its main purpose is to function as an out-of-band mgmt, if the connectivity to the actual management interface is not permitted, so you are right in stating that it is not the actual management interface.
The ping was performed from outside the firewall (user PC).
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY