Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Bachan
Explorer

Vulnerability scan shows ports 18231 uses weak ciphers

Hi Team,

Checkpoint devices showing that weak ciphers are used on port 18231.

Current version on Gateway : R81.20 Take 76.

As per the sk132712 the issue should have been resolved in R81.20 . But we still see this vulnerability in the scan report.

Can you please let us know if there is any other solution to this ?

Attached is the scan report of the same.

 

0 Kudos
3 Replies
Tal_Paz-Fridman
Employee
Employee

I'll forward this to the relevant R&D owner but the SK details how to disable the Legacy Desktop Policy process.

Do you use Policy Server and Desktop Policy enabled?

"For other versions and Jumbo Hotfixes;
You can disable the daemon completely by editing the implied_rules.def, and removing/commenting the relevant lines:"

0 Kudos
PhoneBoy
Admin
Admin

Have you tried disabling dtpsd as described in the SK?

0 Kudos
the_rock
Legend
Legend

Can you try follow below from the sk?

Andy

 

You can disable the daemon completely by editing the implied_rules.def, and removing/commenting the relevant lines:


  1. Open the relevant Gateway object properties in SmartDashboard and uncheck the box “Policy Server” under the “IPSec VPN” blade, click OK (Do not push policy) and close the SmartDashboard.
  2. Open ssh / console connection to the Management Server.
  3. Change directory to $FWDIR/lib : (cd $FWDIR/lib)

    Note: For the location of the implied_rules.def file on the Management server, refer to sk92281.

  4. Open the implied_rules.def file with vim:

    [Expert@HostName:0]# vim implied_rules.def

  5. Comment the following lines:

    Before the change:

    #define ENABLE_FWD_TOPO

    #define ENABLE_FW1_PSLOGON_NG

    After the change:

     /*#define ENABLE_FWD_TOPO*/

     /*#define ENABLE_FW1_PSLOGON_NG*/

  6. Save the modified file.
  7. Install Policy on the relevant gateway.
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events