> Source: [sk177251](https://support.checkpoint.com/results/sk/sk177251)

# sk177251 - Spark Firewall accepts traffic sent to ports configured in built-in SIP services without any allowing rule

| Property | Value |
|----------|-------|
| Solution ID | sk177251 |
| Date Created | 2022-01-13 |
| Last Modified | 2022-07-12 |
| Technical Level | Advanced |
| Products | Spark Firewall (Locally Managed) |
| Versions | R81.10.X |
| Platform | 1570R, 1500, 1600, 1800 |

## Symptoms

- * In security audit default, the SIP/TCP \& UDP ports (5060 and 5061) are shown as open on external interfaces.

* This issue also happens with any manually configured ports in the built-in SIP services: SIP_TCP, SIP_TLS_AUTH,SIP_UDP

* A connection attempt to any of the appliance's internal interfaces on the same ports is dropped.

* A connection attempt to any other not-allowed ports is dropped.

## Cause

In version R80.20.XX, when the Quantum Spark appliance acts as a VoIP device (including built-in VoIP wizard), the configured ports in the built-in SIP services are permanently inspected, which makes them open for external connections such as Telnet, without any Firewall policy rule. All other ports are blocked.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
