cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
7983
Views
0
Helpful
1
Replies

port 1720 always open

musthafa786
Level 1
Level 1

Hi,

I have two layer of firewall , front end is checkpoint and back end is cisco fwsm , when i do nmap port sacn from external network to inside any host I can see port 1720 is as always open , but there is no service running in server with port 1720, I know port 1720 is H.323 call setup protocol used by multimedia collaborative apps such as NetMeeting to establish and control a collaborative session.

could anyone help me on this ?

Regards,

Musthafa.

1 Reply 1

usmanashaikh
Level 1
Level 1

This is coming from the Checkpoint Firewall which inspects traffic for H.323 (1720) so anything behind the firewall appears to be responding to 1720.

https://community.checkpoint.com/t5/Russian/All-hosts-behind-Check-Point-have-open-tcp-1720-port-in-port/td-p/11304

https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk43033

You can disable this behaviour as per the above links

Review Cisco Networking for a $25 gift card