> Source: [sk165937](https://support.checkpoint.com/results/sk/sk165937)

# sk165937 - How to disable the connection to Security Gateway on TCP Port 80 and on TCP Port 443

| Property | Value |
|----------|-------|
| Solution ID | sk165937 |
| Date Created | 2020-03-23 |
| Last Modified | 2026-07-19 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |

## Solution

**Important Notes:**

* After you do these procedures, you will no longer be able to work with Check Point Portals.
* Disabling the ports can affect some Remote-Access/Site-to-Site VPN scenarios.

**This applies to centrally managed Quantum Spark Gateways as well.**

* **To disable the connection to Security Gateway on TCP Port 80 only**

  1. Connect to the Security Gateway command line (via SSH or console).
  2. Log in to Expert mode.
  3. Set the value of the kernel parameter **`multi_portal_allow_redirect`** to **0** (zero):

     * To check the current value of a kernel parameter:

       **`[Expert@HostName]# fw ctl get int multi_portal_allow_redirect`**
     * To set the desired value for a kernel parameter *on-the-fly*:

       **`[Expert@HostName]# fw ctl set int multi_portal_allow_redirect 0`**
     * To set the desired value for a kernel parameter *permanently*:

       Follow [sk26202 (Changing the kernel global parameters for Check Point Security Gateway)](http://supportcontent.checkpoint.com/solutions?id=sk26202).
       1. Create the `$FWDIR/boot/modules/fwkern.conf` file (if it does not already exit):

          **`[Expert@HostName]# touch $FWDIR/boot/modules/fwkern.conf`**
       2. Edit the `$FWDIR/boot/modules/fwkern.conf` file in Vi editor:

          **`[Expert@HostName]# vi $FWDIR/boot/modules/fwkern.conf`**
       3. Add this line (spaces are not allowed):

          **`multi_portal_allow_redirect=0`**   

       4. Save the changes and exit from Vi editor.
       5. Check the contents of the `$FWDIR/boot/modules/fwkern.conf` file:

          **`[Expert@HostName]# cat $FWDIR/boot/modules/fwkern.conf`**   

       6. Reboot the Security Gateway.

  <br />

  <br />

* **To disable the connection to Security Gateway on TCP Port 80 and on TCP Port 443**

  1. Connect to command line on the Security Management Server / Multi-Domain Security Management Server (over SSH, or console).   

  2. Log in to Expert mode.
  3. On the Multi-Domain Security Management Server: switch to the context of the involved Domain Management Server:

     **`[Expert@HostName]# mdsenv `*Domain_Name***
  4. Edit the relevant '`implied_rules.def`' file in Vi editor:

     **`[Expert@HostName]# vi /full_path_to/implied_rules.def`**

     For all the locations, refer to [sk92281 (Creating customized implied rules for Check Point Security Gateway - 'implied_rules.def' file)](http://supportcontent.checkpoint.com/solutions?id=sk92281).

     Comment out this macro at the top of the file:  

     from  
     `#define ENABLE_PORTAL_HTTP_REDIRECT`  

     to  
     `// #define ENABLE_PORTAL_HTTP_REDIRECT`
  5. Save the changes in the file and exit from Vi editor.   

  6. Connect with SmartConsole to the Security Management Server / Domain Management Server.   

  7. Install the policy onto the relevant Security Gateway / Cluster object.

**Important Notes:**

* After you apply the workaround procedure, the TCP connections to the Security Gateway on port 80 / port 443 will fail, but there were still be a log in SmartView Tracker showing that these TCP connections were accepted.
* The connections pass the rulebase by the implied rules, but are then rejected by the CPAS.

<br />

*** ** * ** ***

**Alternative solution** :  
Create SAM rule to block on port 443 and port 80  

The Security Gateway will still display certificate warning whether the rule is set to block HTTPS or not.  
To close out the port completely so that even certificate warning won't show, according to TM-8286:  

*#define ENABLE_TCP_TUNNELING*   

to  

*//#define ENABLE_TCP_TUNNELING*

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
