Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
velo
Collaborator
Jump to solution

SMB listening on HTTPS

Morning

We have an estate of SMB appliances that are centrally managed. During pen tests it has been picked up that they are listening on HTTPS (443). I raised this with TAC and they have said this is normal, and related to management, or VPN. This doesn't seem right to me? Gaia management is on 4434.

Does anybody have any insight into this? If I do a tcpdump the firewalls get scanned on that port from externally (which is expected on the internet) The problem is this is generating unwanted traffic. How can I close this port?

Thanks

 

1 Solution

Accepted Solutions
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

Please review sk105740 it may be useful for you.

If it is indeed RA-VPN related their is an option to instead reserve 443 for port-forwarding / NAT this is an advanced setting at least on locally-managed appliances.

 

 

 

CCSM R77/R80/ELITE

View solution in original post

0 Kudos
2 Replies
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

Please review sk105740 it may be useful for you.

If it is indeed RA-VPN related their is an option to instead reserve 443 for port-forwarding / NAT this is an advanced setting at least on locally-managed appliances.

 

 

 

CCSM R77/R80/ELITE
0 Kudos
velo
Collaborator

Thanks, I believe it's the answer. The article is a little confusing to me and lacks some info. 

I can't find those same settings on the SMB firewalls.

Thanks for the link though.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events