- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Good morning. Since installing our 1575 & creating a server object to forward http requests to, all has been good up until about 2 weeks ago. Our website runs under Server 2019 w/IIS 10 & all of a sudden it stopped answering the call of duty. I have since been working to correct this but just ran out of things to look for. The monitoring screen of the appliance shows what appears to be port 80 being forwarded to the server & Wireshark confirms that the packets are reaching the server. I want to begin the search again starting at the entry point to our network & want to ensure that my settings for port forwarding are correct. I have attached a PDF depicting the settings I created in the appliance. If you have a moment, please take a peek & see if they are correct.
No, this is precisely the use case for a Server object.
Recommend a TAC case: https://help.checkpoint.com
They look correct - hide behind GW and port 80 / 443. What was the last change before it ceased to work ? What can be found in the Webserver logs, compared to the time all still worked ?
The webserver logs are all the same, they only show successful activity. There is no indicator in the server event viewer logs of any failures. The IIS website has a couple rules in the URL Rewrite module, one that creates a reverse proxy & another that redirects from http to https. The website is part of a ERP & so the local LAN accesses it via the same www address & that part of it works without issue. With the local LAN connection, the 1575 activity clearly shows the incoming http request, going back out & then coming back in as a https request. I seriously do not believe the malfunction is with the appliance but either with IIS or the ERP that houses the website. There are no logs to view within the ERP but, it seems to function just fine within the local LAN.
Was remote access VPN recently enabled on the appliance?
If yes please search the device advanced settings for: "reserve port 443"
No, I have not ventured that far with the appliance but, it is one thing that will be turned on at some point.
I would involve CP TAC - working for a time, then not working without any changes is strange at least...
How precisely is the Port Forwarding configured?
If the IP involved is the WAN IP of the gateway, you need to use a Server object (not the NAT rulebase) to do this.
I did create it as a server object based upon what I read here in previous topics dealing with port forwarding. The IP address I set is the internal IP address of the server. Should this have been created using a NAT rule instead? It sounded to me that based upon the incoming port by the caller, if it matched 80 or 443, the 1575 would port forward the call automatically. It has been working like this for a while. Certainly a lot to understand the operational characteristics of this 1575 that I keep trying to squeeze in among everything else.
No, this is precisely the use case for a Server object.
Recommend a TAC case: https://help.checkpoint.com
Have an update on this. Spent almost 2 hours with a CP tech today. The issue is still under investigation but after reviewing the logs with him, the 1575 appliance is forwarding the incoming port 80 HTTP requests to the web server but, it is forwarding them on a random TCP port. The IIS website is bound to port 80 & 443 so, I (we) are assuming that the port forward will not be answered by IIS due to it not being on the correct port. Kind of befudding....
It definitely should not forward to a random TCP port.
Sounds like a bug.
So, am I correct in stating that within the CP server document in Access Policy settings, when the server is configured as a Web Server with ports 80 & 443 assigned, when the appliance receives a call on port 80, the appliance is supposed to forward that call to the web server on the same port? As it is now, it comes in on port 80, gets forwarded to the server but it gets sent to the server on some other random port number.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
13 | |
5 | |
4 | |
4 | |
3 | |
3 | |
2 | |
2 | |
2 | |
2 |
Tue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAThu 18 Sep 2025 @ 02:00 PM (EDT)
Bridge the Unmanaged Device Gap with Enterprise Browser - AmericasTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAThu 18 Sep 2025 @ 02:00 PM (EDT)
Bridge the Unmanaged Device Gap with Enterprise Browser - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY