> Source: [sk158632](https://support.checkpoint.com/results/sk/sk158632)

# sk158632 - Remote firewall sends traffic to a private IP of the Security Management Server on port 18191

| Property | Value |
|----------|-------|
| Solution ID | sk158632 |
| Date Created | 2019-07-18 |
| Last Modified | 2019-07-18 |
| Technical Level | Advanced |
| Products | Security Management Server |
| Versions | R82.10, R82, R81.20, R82.x, R82.20 |
| Platform | GCP |

## Symptoms

- * The firewall sends traffic to a private IP of the Security Management Server on port 18191.
* The following is the output of the CPD debug from the Firewall:

  ```
  
  [CPD 18384 4133865216]@Firewall[DATE  TIME] call_handlers_list: no conversion done, set CN=Firewall,..... as sic name
  [CPD 18384 4133865216]@Firewall[DATE  TIME] PM_session_init: given session I(cn=cp_mgmt,.....;18191;LSMServerAddon).
  [CPD 18384 4133865216]@Firewall[DATE  TIME] PM_policy_query: input session I(cn=cp_mgmt,.....;18191;LSMServerAddon).
  [CPD 18384 4133865216]@Firewall[DATE  TIME] PM_policy_query: rule found (DN_Mgmt;ANY;ANY;LSMServerAddon;sslca(1/2)).
  [CPD 18384 4133865216]@Firewall[DATE  TIME] PM_policy_query: finished successfully. 1st method = sslca
  ```

* Editing *$FWDIR/conf/masters* or */etc/hosts/* does not have any effect.
* Deleting *$FWDIR/database/smart-center-servers.properties* works temporarily, but the file is created again when the policy is pushed.

## Cause

By design, the initiated session on port 18191 is generated by periodical checks of SmartProvisioning to the IP configured on the Security Management Server. This is enabled on the Security Management Server by default in R80.xx

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
