Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
tavi0906
Contributor

disable ICA port

We need to disable the ICA port as we are not using it for CRL. 

is there a way to disable the service?

Please let us have the SK for it. 

 

0 Kudos
5 Replies
the_rock
Legend
Legend

You can run ps -auxw | grep 18265 and then once you have an ID, run kill -9 pid (whatever the number)

Alternatively, you can create a rule to block it. Btw, are you sure its not needed at all? ICA is as a matter of fact authority responsible for issuing certificates for SIC.

Andy

0 Kudos
the_rock
Legend
Legend

Here is the sk.

Andy

https://support.checkpoint.com/results/sk/sk30501

https://support.checkpoint.com/results/sk/sk102837

 

If ICA Management Tool is currently enabled (ON), but is not needed, then perform one of the following:

  • Either disable ICA Management Tool:

    • On Security Management Server

      [Expert@HostName]# cpca_client set_mgmt_tool off

    • On Multi-Domain Security Management Server

      [Expert@HostName]# mdsenv Domain_Name
      [Expert@HostName]# cpca_client set_mgmt_tool off
0 Kudos
PhoneBoy
Admin
Admin

That’s for the ICA Management Tool, not the CRL.

SIC (used for firewall/management communication) uses certificates for authentication.
A CRL is a critical part of that process and cannot be disabled.

the_rock
Legend
Legend

Good point. Not sure if what I said in my first reply would even work then...

Andy

0 Kudos
the_rock
Legend
Legend

FWIW, this is what AI Copilot gave...

Andy

********************************************

Disabling the ICA (Internal Certificate Authority) port on Check Point is not recommended as it is crucial for the secure communication between the Security Management Server and the Security Gateways. The ICA is responsible for issuing certificates for authentication and is an integral part of the Check Point security infrastructure.

However, if you have a specific requirement or issue, please provide more details so I can assist you better. If you need to restrict access to the ICA port, you can consider configuring firewall rules to control the traffic.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events