> Source: [sk102367](https://support.checkpoint.com/results/sk/sk102367)

# sk102367 - How to hide port 443 on locally managed embedded GAIA devices

| Property | Value |
|----------|-------|
| Solution ID | sk102367 |
| Date Created | 2014-09-15 |
| Last Modified | 2023-05-07 |
| Technical Level | General |
| Products | Spark Firewall (Locally Managed) |
| Versions | R81.10.X |
| Platform | 6, 20, 400, 1570R, 110, 1500, 1600, 1800, 910 |

## Symptoms

- Running port scans on firewall shows 443 with no servers defined.

## Solution

Two scenarios:

1) Customer is using Remote Access blade (RA)

2) Customer does not use RA

In scenario 1, if customer requires to use RA then it is not be possible completely hide because the firewall will be listening on port 443 by default for RA clients. It is of course possible to change the default port to a different one (for example 4434).

For scenario 2, if you just don't want external scanners to show port 443 to be opened and show any failures to PCI Compliancy scanners like Trustwave, then you can simply follow these steps:

1) Go to Device \> Advanced Settings and search for "Remote Access port" (Lower case "port").

2) Make sure it is set to 443 and "Reserve port 443 for port forwarding" is enabled.

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk102367/4431507302110.PNG)

3) Optional: Go to Home \> Security Dashboard and make sure "Remote Access" is turned off.

You can now scan to see if 443 is still open or fails a security scan.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
