Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
jarvis_dantsrib
Participant
Jump to solution

Connections to Checkpoint native services do not encrypt within the VPN for firewall management

Hello, I am facing a problem where connections on service port 18191 and Checkpoint native services are not encrypted within the VPN, as a consequence it is not possible to manage the firewall and install policy of the remote unit via LAN IP.

The interesting thing is that only Checkpoint service traffic is not encrypted, but ICMP, SSH, HTTPS and other non-native services are encrypted within the VPN.


It is possible to see that there is a match in implicit accept rules, but the traffic is encrypted.

0 Kudos
2 Solutions

Accepted Solutions
emmap
Employee
Employee

This is by design, the CP service traffic is already encrypted and is required to be working to set up a VPN to a remote device over the internet as you need to install the policy to get the VPN going. As such we don't tunnel it by default. You can change this behaviour, but at your risk.

https://support.checkpoint.com/results/sk/sk104582

View solution in original post

3 Replies
emmap
Employee
Employee

This is by design, the CP service traffic is already encrypted and is required to be working to set up a VPN to a remote device over the internet as you need to install the policy to get the VPN going. As such we don't tunnel it by default. You can change this behaviour, but at your risk.

https://support.checkpoint.com/results/sk/sk104582

jarvis_dantsrib
Participant

Hello, This SK is not accessible to me

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 20 May 2025 @ 11:30 AM (PDT)

    Las Vegas: Check Point Hybrid Mesh

    Wed 21 May 2025 @ 11:30 AM (MST)

    Tempe, AZ: Check Point Hybrid Mesh

    Tue 03 Jun 2025 @ 06:00 PM (EDT)

    Montreal: CPX Recap

    Tue 10 Jun 2025 @ 06:00 PM (EDT)

    Quebec City: CPX Recap
    CheckMates Events