> Source: [sk132712](https://support.checkpoint.com/results/sk/sk132712)

# sk132712 - Vulnerability scan shows ports 18231 and 264 open under LISTEN mode when using TLS1.0 and TLS1.1 - reference CVE-2000-1201

| Property | Value |
|----------|-------|
| Solution ID | sk132712 |
| Date Created | 2018-07-31 |
| Last Modified | 2026-02-09 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * Vulnerability scan may show issues with ports 18231 and 264 when using TLS1.0 and TLS1.1

* The port scan (Nmap) may show port 18231 under LISTEN mode when using low TLS versions, for example:  

  ```
  
  PORT      STATE SERVICE
  18231/tcp open  unknown
    ssl-enum-ciphers: 
      TLSv1.0: 
        ciphers: 
          TLS_DH_anon_WITH_AES_128_CBC_SHA - F
          TLS_DH_anon_WITH_AES_256_CBC_SHA - F
        compressors: 
          NULL
        cipher preference: client
      TLSv1.1: 
        ciphers: 
          TLS_DH_anon_WITH_AES_128_CBC_SHA - F
          TLS_DH_anon_WITH_AES_256_CBC_SHA - F
  ...
  ```

  <br />

* Users can review if the port is under LISTEN mode with the following commands:

  ```
  
  [Expert@hostname:0]# netstat -tulnp |grep 18231
  ```

  Or

  ```
  
  [Expert@hostname:0]# netstat ?atun |grep 18231
  ```

  The output is similar to the following:

  ```
  
  [Expert@hostname:0]# tcp 0 0 0.0.0.0:18231 0.0.0.0:* LISTEN 9456/dtpsd
  ```

  <br />

* Vulnerability scan on the gateway shows that we are vulnerable to CVE-2000-1201: Check Point FireWall-1 allows remote attackers to cause a denial of service (high CPU) via a flood of packets to port 264.

## Cause

In the past, there was a use of these ports with SecureClient and DTPSD.

It was used for installation of Desktop Security policy from the Policy Server (DTPSD daemon) to the SecureClient.

Currently, this feature is not used anymore, therefore we can limit the usage of the service.

## Solution

This problem was fixed. The fix is included in:

* [**Check Point R81**](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk166715)
* [**Check Point R80.40**](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk160736&partition=Basic&product=All)
* **[Jumbo Hotfix Accumulator for R80.30 (R80_30_jumbo_hf)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk153152&partition=Basic&product=Endpoint) - starting Take 227**
* **[Jumbo Hotfix Accumulator for R80.20 (R80_20_jumbo_hf)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk137592&partition=Basic&product=All) - starting Take 187**

Check Point recommends to always upgrade to the most recent version.  

Check Point recommends to always upgrade to the most recent version ([upgrade Security Gateway](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=435) / [upgrade Security Management Server](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=184) / [upgrade Multi-Domain Security Management](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=166)).  

For **other versions** and Jumbo Hotfixes:  
You can disable the daemon completely by editing the *implied_rules.def*, and removing/commenting the relevant lines:

1. Open the relevant Gateway object properties in SmartDashboard and uncheck the box "Policy Server" under the "IPSec VPN" blade, click OK (Do not push policy) and close the SmartDashboard.
2. Open ssh / console connection to the **Management Server**.
3. Change directory to *$FWDIR/lib* : (*cd $FWDIR/lib* )

   **Note:** For the location of the *implied_rules.def* file on the Management server, refer to [sk92281](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92281).
4. Open the *implied_rules.def* file with vim:  

   *\[Expert@HostName:0\]# vim implied_rules.def*
5. Comment the following lines:  

   **Before the change:**

   *#define ENABLE_FWD_TOPO*

   *#define ENABLE_FW1_PSLOGON_NG*

   **After the change:**

   */\*#define ENABLE_FWD_TOPO\*/*

   */\*#define ENABLE_FW1_PSLOGON_NG\*/*
6. Save the modified file.
7. Install Policy on the relevant gateway.

<br />

**Note: Performing the procedure above will stop the implied rules from accepting traffic on these ports and should be performed on the Management Server.**   

VPND will still listen to port 264. In order to make VPND stop listening to port 264 please contact support and ask for a portfix for PRHF-5394 for R80.10/20/30.  
In versions R80.40 and higher the fix is integrated and you only need to perform the procedure below.  
**Note:** In versions R82 and higher, port 264 is closed by default and you do not need to do this procedure.  

Once the fix is installed the following procedure will be needed to enable it:  
1. Open ssh / console connection to the **Gateway** .  
2. \[Expert@hostname:0\]# ckp_regedit -a SOFTWARE\\\\CheckPoint\\\\VPN1 TOPO_SRV_ENABLED -n 0  
3. \[Expert@hostname:0\]# cpstop \&\& cpstart (or 'fw kill vpnd' to minimise downtime)  
0 = do not listen on port 264  
1 = do listen on port 264  

<br />

**NOTE:** In some rare cases once the procedure above is done SmartConsole will show red X next to the gateway object the procedure was done for, with warning saying "policy server is not responding . . . "  

This can be solved by asking support for a portfix of PRHF-6542  

<br />

<br />

<br />

<br />

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
