Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
tavi0906
Contributor

disable ICA port

We need to disable the ICA port as we are not using it for CRL. 

is there a way to disable the service?

Please let us have the SK for it. 

 

0 Kudos
7 Replies
the_rock
Legend
Legend

You can run ps -auxw | grep 18265 and then once you have an ID, run kill -9 pid (whatever the number)

Alternatively, you can create a rule to block it. Btw, are you sure its not needed at all? ICA is as a matter of fact authority responsible for issuing certificates for SIC.

Andy

0 Kudos
the_rock
Legend
Legend

Here is the sk.

Andy

https://support.checkpoint.com/results/sk/sk30501

https://support.checkpoint.com/results/sk/sk102837

 

If ICA Management Tool is currently enabled (ON), but is not needed, then perform one of the following:

  • Either disable ICA Management Tool:

    • On Security Management Server

      [Expert@HostName]# cpca_client set_mgmt_tool off

    • On Multi-Domain Security Management Server

      [Expert@HostName]# mdsenv Domain_Name
      [Expert@HostName]# cpca_client set_mgmt_tool off
0 Kudos
PhoneBoy
Admin
Admin

That’s for the ICA Management Tool, not the CRL.

SIC (used for firewall/management communication) uses certificates for authentication.
A CRL is a critical part of that process and cannot be disabled.

the_rock
Legend
Legend

Good point. Not sure if what I said in my first reply would even work then...

Andy

0 Kudos
tavi0906
Contributor

is there any specific command to restart the ICA services or do i need to restart the firewall?

0 Kudos
PhoneBoy
Admin
Admin

While I believe it's the cpd process that needs to be killed, it's best to perform a cprestart here (which if executed on a gateway, will "restart the firewall").

0 Kudos
the_rock
Legend
Legend

FWIW, this is what AI Copilot gave...

Andy

********************************************

Disabling the ICA (Internal Certificate Authority) port on Check Point is not recommended as it is crucial for the secure communication between the Security Management Server and the Security Gateways. The ICA is responsible for issuing certificates for authentication and is an integral part of the Check Point security infrastructure.

However, if you have a specific requirement or issue, please provide more details so I can assist you better. If you need to restrict access to the ICA port, you can consider configuring firewall rules to control the traffic.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 18 Mar 2025 @ 09:30 AM (EET)

    CheckMates Live Greece

    Tue 25 Mar 2025 @ 12:00 PM (MDT)

    Salt Lake City: CPX 2025 Recap

    Tue 08 Apr 2025 @ 12:00 PM (MDT)

    Denver: CPX 2025 Recap
    CheckMates Events