CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SecureClient/SecuRemote
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-04-09
gchow gchow is offline
Junior Member
 
Join Date: 2007-11-14
Posts: 11
Rep Power: 0
gchow has an average reputation (10+)
Default protocol 50

What is mean by protocol 50 ?
Is UDP or TCP?
Does it use port 50?
How to create?
Thanks.

The following is the suggest solution found in checkpoint, but I have the above question which related to this solution


Solution ID: sk13187 Previous Next


Ports and IP protocol numbers needed to be opened on a non-VPN gateway to enable SecuRemote/SecureClient traffic


Product: VPN-1 Pro (VPN-1/FW-1)
Version: NG, NG AI, NGX
Last Modified: 26-Sep-2007
Print this Solution
Email this Solution
Back to Results List







Solution



Here is the list of ports and IP Protocol numbers that need to be open:


protocol 50 for ESP

UDP 2746 for UDP Encapsulation

UDP 500 for IKE

TCP 500 for IKE over TCP

TCP 18231 for Policy Server logon when the client is inside the network

UDP 18233 for Keepalive protocol when the client is inside the network

TCP 18232 for Distribution Server when the client is inside the network (Version NG)

TCP 264 for topology download

UCP 259 for MEP configuration

UDP 18234 for performing tunnel test when the client is inside the network

UDP 4500 for IKE and IPSEC (NAT-T)

TCP 18264 for ICA certificate registration

Note: MEP's UDP RDP packets are not encrypted, and only test the availability of a peer gateway. RDP (UDP port 259) connections to gateways are allowed by the "Accept FireWall-1 Control Connections" property.

Related Solution
sk17745: What services are allowed by the "Accept FireWall-1 Control Connections" property
Reply With Quote
  #2 (permalink)  
Old 2008-04-10
abusharif abusharif is offline
Senior Member
 
Join Date: 2006-04-27
Location: Twillight zone
Posts: 442
Rep Power: 3
abusharif has an average reputation (10+)
Default Re: protocol 50

Protocols:ESP - Colasoft
Reply With Quote
  #3 (permalink)  
Old 2008-04-10
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: protocol 50

Protocol 50 is already defined on the check Point, as ESP. It's at the same level as TCP, UDP, ICMP (which also have their protocol numbers).

This is used on VPNs and usually you will want a rule allowing ESP between all the VPN gateways. This is part of the implied rules and doesn't need to be created, unless you disable them.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 06:26.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0