Skip to main content

Posts

Showing posts from September, 2017

Checkpoint Firewall Ports

Check Point General Common Ports PORT TYPE SERVICE DESCRIPTION 257 tcp FireWall-1 log transfer 18208 tcp CPRID (SmartUpdate) 18190 tcp SmartDashboard to SCS 18191 tcp SCS to FW-1 gateway for policy install 18192 tcp SCS monitoring of firewalls (SmartView Status) Check Point SIC Ports PORT TYPE SERVICE DESCRIPTION 18209 tcp NGX Gateways <> ICAs (status, issue, or revoke). 18210 tcp Pulls Certificates from an ICA. 18211 tcp Used by the cpd daemon (on the gateway) to receive Certificates. PORT TYPE SERVICE DESCRIPTION 94 TCP Encryption IP protocols fwz_encapsulation (FW1_Eencapsulation) 137 Both Netbios-ns NETBIOS Name Service 138 Both netbios-dgm NETBIOS Datagram 139 Both netbios-ssn NETBIOS Session 256 TCP FW1 (fwd) policy install port FWD_SVC_PORT 257 TCP FW1_log FW1_log FWD_LOG_PORT 258 TCP FW1_mgmt FWM_SSVVC_PORT 259 TCP FW1_clientauth_telnet 260 UDP FW1_snmp FWD_SNMP_PORT 261 TCP FW1_snauth Session Authentication Daemon 262 TCP MDQ – mail deque

Command to check on Checkpoint Bond Interface status

[Expert@fw01:0]# cphaprob -a if Required interfaces: 3 Required secured interfaces: 1 Mgmt       Disconnected          non sync(non secured), multicast bond0      UP                    non sync(non secured), broadcast, bond Load Sharing bond1      UP                    non sync(non secured), broadcast, bond Load Sharing bond2      UP                    sync(secured), multicast, bond Load Sharing [Expert@fw01:0]# cphaconf show_bond -a                                       |Slaves     |Slaves |Slaves Bond name  |Mode               |State |configured |in use |required -----------+-------------------+------+-----------+-------+-------- bond0      | Load Sharing      | UP   | 2         | 2     | 1 bond1      | Load Sharing      | UP   | 2         | 2     | 1 bond2      | Load Sharing      | UP   | 1         | 1     | 0 Legend: ------- UP!               - Bond interface state is UP, yet attention is required Slaves configured - number of slave interface