Hi All,
Our vulnerability scanner shown port 80, 443, 500 and 18264 are open on external interfaces of our firewall. We are not using SSL VPN or remote access VPN on this firewall but we have IPSec Site to Site VPN Tunnel on it. I have disabled few settings
- VPN Clients > Desktops / Laptops Windows and Mac clients
- VPN Clients > Authentication > allow older client to connect this gateway
- VPN Client > Remote Access > Allow remote clients to route the traffic through this gateway
- Mobile Access > Web - SSL vpn with Web Browser
But still the above mentioned ports are open and as per SOC team they are insisting me to block access to this ports from the external word. I need help here can anyone please suggest what needs to be done fix this.