Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
EricRobert
Participant
Jump to solution

Security Gateway starts to listen on port 80, 264 and 443 after upgrade from R81.10 to R81.20

Hi,

We are monitoring our outside interface to be sure that they are not visible from the Internet, but immediatly after an upgrade from R81.10 to R81.20, a scan revealed that TCP ports 80, 264 and 443 are now listening on outside interface.

 

How can we disable listening ports on outside interface ?

Thanks

0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin

Those ports are typically allowed through implied rules.
If you've edited .def files to disable certain rules, those changes do not propagate through an upgrade.

The correct way to disable these implied rules for 80/443 is through configuration: https://support.checkpoint.com/results/sk/sk105740 
To ensure that TCP port 264 isn't listening, see: https://support.checkpoint.com/results/sk/sk132712 
You may need to perform the "regedit" portion of the SK to disable the relevant process that listens on this port.

View solution in original post

2 Replies
Lesley
Leader Leader
Leader

I think some custom changes on previous version have been lost after upgrade. Did you do clean install?

start with 

https://support.checkpoint.com/results/sk/sk132712

also check if traffic is allowed by explicit rule or implied rule. In traffic logs if you can see it is hit on rule 0 it is an implied rule. 

-------
If you like this post please give a thumbs up(kudo)! 🙂
PhoneBoy
Admin
Admin

Those ports are typically allowed through implied rules.
If you've edited .def files to disable certain rules, those changes do not propagate through an upgrade.

The correct way to disable these implied rules for 80/443 is through configuration: https://support.checkpoint.com/results/sk/sk105740 
To ensure that TCP port 264 isn't listening, see: https://support.checkpoint.com/results/sk/sk132712 
You may need to perform the "regedit" portion of the SK to disable the relevant process that listens on this port.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events