I have a Check Point Security Management Server that is NATed to a public IP, and I’ve noticed that port 19009 (used by SmartConsole, CPM service) is accessible from the internet due to an implied rule, even though I have configured the GUI Clients list. My setup is running R81.20 take 113.
Questions:
Why is the GUI Clients list not restricting network-level access to port 19009, allowing internet connections via an implied rule?
How can I configure the SMS to block access to port 19009 from the internet, ensuring only IPs in the GUI Clients list can connect?