- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: disable ICA port
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
disable ICA port
We need to disable the ICA port as we are not using it for CRL.
is there a way to disable the service?
Please let us have the SK for it.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can run ps -auxw | grep 18265 and then once you have an ID, run kill -9 pid (whatever the number)
Alternatively, you can create a rule to block it. Btw, are you sure its not needed at all? ICA is as a matter of fact authority responsible for issuing certificates for SIC.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Here is the sk.
Andy
https://support.checkpoint.com/results/sk/sk30501
https://support.checkpoint.com/results/sk/sk102837
If ICA Management Tool is currently enabled (ON), but is not needed, then perform one of the following:
-
Either disable ICA Management Tool:
-
On Security Management Server
[Expert@HostName]# cpca_client set_mgmt_tool off
-
On Multi-Domain Security Management Server
[Expert@HostName]# mdsenv Domain_Name
[Expert@HostName]# cpca_client set_mgmt_tool off
-
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That’s for the ICA Management Tool, not the CRL.
SIC (used for firewall/management communication) uses certificates for authentication.
A CRL is a critical part of that process and cannot be disabled.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Good point. Not sure if what I said in my first reply would even work then...
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
is there any specific command to restart the ICA services or do i need to restart the firewall?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
While I believe it's the cpd process that needs to be killed, it's best to perform a cprestart here (which if executed on a gateway, will "restart the firewall").
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
FWIW, this is what AI Copilot gave...
Andy
********************************************
Disabling the ICA (Internal Certificate Authority) port on Check Point is not recommended as it is crucial for the secure communication between the Security Management Server and the Security Gateways. The ICA is responsible for issuing certificates for authentication and is an integral part of the Check Point security infrastructure.
However, if you have a specific requirement or issue, please provide more details so I can assist you better. If you need to restrict access to the ICA port, you can consider configuring firewall rules to control the traffic.
- Quantum Spark R80.20.10 Locally Managed Administration Guide for 1500 Appliances - Managing-System-S...
- R77 Versions Installation and Upgrade Guide for Non-Gaia Platforms - 16248
- Quantum Spark R80.20.15 Locally Managed Administration Guide for 1500 Appliances - Managing-System-S...
- R82 Security Management Administration Guide - cpca_client-get_crldp
- R77 Versions Installation and Upgrade Guide for Gaia Platforms - 16248
- sk172384 - Port Scanning shows Port 12873 is open on the Security Gateway
- R80.40 Remote Access VPN Administration Guide - Check-Point-VPN
- R81 Remote Access VPN Administration Guide - Check-Point-VPN
- sk99130 - SIC with the Security Gateway breaks every few days and SIC error "Authentication error [e...
- sk52421 - Ports used by Check Point software
