I found that ftp command with public IP interface of the checkpoint gateway response all of the IP addresses on my public interface subnet. (Also with telnet port 21 command)
Although the connection close or timeout but it is still shown the message '220 Check Point FireWall-1 Secure FTP server running on XXX' when I try to using ftp x.x.x.x.
I try to block this FTP access from internet by creating stealth rule for my public IP destination with FTP service. It's work. But I still don't know why the gateway response FTP connection like this and I want to disable it.
I'm using 4600 running R77.30 Gaia.