- CheckMates
- :
- Products
- :
- Quantum
- :
- Remote Access VPN
- :
- Re: Close port 80
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Close port 80
Hello
Could you please advise me how to close port 80 on a cluster only on external interfaces? Now we see that the cluster is accessible from the Internet on port 80. In the logs this connection passes through implied rules.
I found https://support.checkpoint.com/results/sk/sk165937. Do I understand correctly that these recommendations only close ports on external interfaces?
We are using Remote Access VPN and S2S VPN. If we close port 80, will it affect the VPN work?
Please answer these questions.
Thank you in advance.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi
I checked sk52421. Really, tcp 80 is not used anywhere.
I think I will make the recommendations from sk165937 to close port 80.
Thanks!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Polina_1
I think you can safely disable tcp/80. Otherwise security over all, if I were you I would close the tcp/80 port.
Check this communication matrix:
source: https://support.checkpoint.com/results/sk/sk52421
Akos
\m/_(>_<)_\m/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
RA vpn relies on https. Btw, cant open the sk you referenced.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Any, delete the dot by the end of the line 🙂
\m/_(>_<)_\m/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@AkosBakos DOH...Homer Simpson moment, haha, tx bud. @Polina_1 Yes, I believe that applies to external interfaces.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi
I checked sk52421. Really, tcp 80 is not used anywhere.
I think I will make the recommendations from sk165937 to close port 80.
Thanks!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would say thats your best bet.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Create nat rule to a fake ip address
