- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
What does Port 18192 do exactly?
I can see traffic every minute from our secondary management server to a few of our gateways (on port 18192)
I can see that they have a 'lost' status, but it doesn't appear to be SIC related.
Is it something like certain config not being exported/imported properly?
What can we do to stop this please
Many thanks
It is for the CPD AMON (Application Monitoring):
Check Point internal Application Monitoring (AMON) connections between Security Gateway and Management Server / SmartReporter Server / SmartEvent Server (CPD daemon)
Ports used by Check Point software:
https://support.checkpoint.com/results/sk/sk52421
So basically used to deliver monitoring information from the remote machines to the Security Management Server.
Because the Security Gateways are also aware of the Secondary Management Server as a "Management" they try to deliver status information.
Backup management does not run the cpstat_monitor process (only active unit).
As stated in: https://support.checkpoint.com/results/sk/sk35278
This process is used for information in Smartview Monitor, I think that is why you have lost status.
You can test it to make the stand-by unit active and see if then the issue gone.
Regarding the 18192 port this is required to be allowed:
| CP | 18192 | CPD_amon - Check Point Internal Application Monitoring | Check Point internal Application Monitoring (AMON) connections between Security Gateway and Management Server / SmartReporter Server / SmartEvent Server (CPD daemon) |
It is for the CPD AMON (Application Monitoring):
Check Point internal Application Monitoring (AMON) connections between Security Gateway and Management Server / SmartReporter Server / SmartEvent Server (CPD daemon)
Ports used by Check Point software:
https://support.checkpoint.com/results/sk/sk52421
So basically used to deliver monitoring information from the remote machines to the Security Management Server.
Because the Security Gateways are also aware of the Secondary Management Server as a "Management" they try to deliver status information.
Backup management does not run the cpstat_monitor process (only active unit).
As stated in: https://support.checkpoint.com/results/sk/sk35278
This process is used for information in Smartview Monitor, I think that is why you have lost status.
You can test it to make the stand-by unit active and see if then the issue gone.
Regarding the 18192 port this is required to be allowed:
| CP | 18192 | CPD_amon - Check Point Internal Application Monitoring | Check Point internal Application Monitoring (AMON) connections between Security Gateway and Management Server / SmartReporter Server / SmartEvent Server (CPD daemon) |
You definitely got the right answers. The sk @Tal_Paz-Fridman provided is probably the best reference.
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 11 | |
| 9 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY