> Source: [sk105719](https://support.checkpoint.com/results/sk/sk105719)

# sk105719 - CPMI/CPM traffic from remote SmartConsole client to the Management Server is not encrypted, but accepted by Implied Rules instead

| Property | Value |
|----------|-------|
| Solution ID | sk105719 |
| Date Created | 2015-04-15 |
| Last Modified | 2025-05-22 |
| Technical Level | Advanced |
| Products | Security Management Server, SmartConsole |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS), R82, R81.20, R81.10 (EOS), R81 (EOS) |

## Symptoms

- * In the below topology, connections with the SmartConsole client (CPMI/CPM traffic) from the remote SmartConsole client to the Management Server should be encrypted and sent over the VPN tunnel. However, CPMI/CPM traffic is accepted by Implied Rules instead.

  Example Topology:  

  Remote SmartConsole client --- \[GW1\] === VPN === \[GW2\] --- Management_Server
* SmartView Tracker / SmartLog log shows that traffic to "Management_Server" was just accepted by Implied Rules:

  ```
  
  Type: Log
  Action: Accept
  Service: CPMI (18190)
  Destination: <MGMT_SERVER>
  Protocol: tcp
  Rule: 0 - Implied Rules
  Community: <COMMUNITY_NAME>
  Information: inzone: Internal
               outzone: External
                      service_id: CPMI
                      message_info: Implied rule
  ```

* SmartLog log is expected to show that CPMI/CPM traffic to "Management_Server" was encrypted by "GW1" and sent over the VPN tunnel to "GW2":

  ```
  
  Type: Log
  Action: Encrypt
  Service: CPMI (18190)
  Destination: <MGMT_SERVER>
  Protocol: tcp
  Rule: <NUMBER>
  Rule UID: {... ...}
  Rule Name: <RULE_NAME>
  Community: <COMMUNITY_NAME>
  Information: inzone: Internal
               outzone: External
                      service_id: CPMI
  Encryption Scheme: IKE
  VPN Peer Gateway: <GW2>
  ```

## Cause

By design, when "*Accept control connections* " option is enabled in the Global Properties (in SmartConsole - click on *Global Properties...* in the drop-down menu on the left-top - go to *FireWall* pane), the CPMI/CPM traffic (connections with SmartConsole to the Security Management Server) is matched by the Security Gateway to the Implied Rules and the Security Gateway accepts this traffic regardless of rulebase or VPN configuration.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
