ports commonly used in Check Point firewall-1 setups:
| Check Point native | service name | |
| IP protocol 94 | SecuRemote FWZ Encapsulation Protocol | FW1_encapsulation |
| tcp port 256 | Check Point VPN-1 & FireWall-1 Service | FW1 |
| tcp port 257 | Check Point VPN-1 & FireWall-1 logs | FW1_log |
| tcp port 258 | Check Point management (4.x) | FW1_mgmt |
| tcp port 259 | Check Point VPN-1 & FireWall-1 client authentication | FW1_clntauth_telnet |
| tcp port 259 | Check Point VPN-1 & FireWall-1 client authentication | FW1_clntauth_telnet |
| tcp port 260 | Check Point VPN-1 & FireWall-1 SNMP agent | FW1_snmp |
| tcp port 264 | Check Point VPN-1 SecureRemotetopology | FW1_topo |
| tcp port 265 | Public Key Transfer Protocol | FW1_key |
| tcp port 900 | Client Authentication (HTTP) | FW1_clntauth_http |
| tcp port 257 | Check Point VPN-1 & FireWall-1 logs | FW1_log |
| tcp port 2746 | Check Point VPN-1 SecuRemote IPSEC encapsulation | VPN1_IPSEC_encapsulation |
| tcp port 18184 | Check Point OPSEC log export API | FW1_lea |
| tcp port 18187 | Check Point OPSEC event logging API | FW1_ela |
| tcp port 18190 | Check Point management interface | CPMI |
| tcp port 18192 | Check Point internal application monitoring | CPD_amon |
| tcp port 18231 | Check Point NG policy logon protocol | FW1_pslogon_NG |
| tcp port 18233 | Check Point SecureClient Verification keepalive | FW1_scv_keep_alive |
| tcp port 18264 | Check Point internal CA fetch CRL | FW1_ica_services |
| Other standards | ||
| udp port 500 | IPSec VPN IKE negotiations (ISAKMP) | |
| tcp port 500 | IPSec VPN IKE negotiations over tcp(ISAKMP) | |
| IP protocol 50 | IPSec VPN ESP protocol | |
| IP protocol 51 | IPSec VPN AH protocol | |
| udp port 1701 | L2TP tunneling protocol | |
| tcp port 1723 | PPTP point-to-point tunneling protocol | |
| IP protocol 47 | GRE for PPTP payload |
most common protocol numbers (source iana.org)
| 1 | ICMP | Internet Control Message | [RFC792] |
| 6 | TCP | Transmission Control | [RFC793] |
| 17 | UDP | User Datagram | [RFC768] |
| 47 | GRE | General Routing Encapsulation | |
| 50 | ESP | Encap Security Payload | [RFC2406] |
| 51 | AH | Authentication Header | [RFC2402] |
| 112 | VRRP | Virtual Router Redundancy Protocol | |
| 115 | L2TP | Layer Two Tunneling Protocol |
well known port numbers (source iana.org)
| ftp-data | 20/tcp | File Transfer [Default Data] |
| ftp | 21/tcp | File Transfer [Control] |
| ssh | 22/tcp | SSH Remote Login Protocol |
| telnet | 23/tcp | Telnet |
| smtp | 25/tcp | Simple Mail Transfer |
| dns | 53/tcp | zone transfer |
| dns | 53/udp | dns query |
| sql*net | 66/tcp | Oracle SQL*NET |
| sql*net | 66/udp | Oracle SQL*NET |
| tftp | 69/tcp | Trivial File Transfer |
| tftp | 69/udp | Trivial File Transfer |
| finger | 79/tcp | Finger |
| finger | 79/udp | Finger |
| http | 80/tcp | World Wide Web HTTP |
| HTTP | 81/tcp | commonly used to administer ISS |
| kerberos | 88/tcp | Kerberos |
| npp | 92/tcp | Network Printing Protocol |
| npp | 92/udp | Network Printing Protocol |
| pop3 | 110/tcp | Post Office Protocol - Version 3 |
| pop3 | 110/udp | Post Office Protocol - Version 3 |
| sunrpc | 111/tcp | SUN Remote Procedure Call |
| sunrpc | 111/udp | SUN Remote Procedure Call |
| auth | 113/tcp | Authentication Service |
| auth | 113/udp | Authentication Service |
| sqlserv | 118/tcp | SQL Services |
| sqlserv | 118/udp | SQL Services |
| nntp | 119/tcp | Network News Transfer Protocol |
| nntp | 119/udp | Network News Transfer Protocol |
| ntp | 123/tcp | Network Time Protocol |
| ntp | 123/udp | Network Time Protocol |
| rpc | 135/tcp | remote procedure call |
| rpc | 135/udp | remote procedure call |
| netbios-ns | 137/tcp | NETBIOS Name Service |
| netbios-ns | 137/udp | NETBIOS Name Service |
| netbios-dgm | 138/tcp | NETBIOS Datagram Service |
| netbios-dgm | 138/udp | NETBIOS Datagram Service |
| netbios-ssn | 139/tcp | NETBIOS Session Service |
| netbios-ssn | 139/udp | NETBIOS Session Service |
| imap | 143/tcp | Internet Message Access Protocol |
| imap | 143/udp | Internet Message Access Protocol |
| sql-net | 150/tcp | SQL-NET |
| sql-net | 150/udp | SQL-NET |
| sqlsrv | 156/tcp | SQL Service |
| sqlsrv | 156/udp | SQL Service |
| snmp | 161/tcp | SNMP |
| snmp | 161/udp | SNMP |
| snmptrap | 162/tcp | SNMPTRAP |
| snmptrap | 162/udp | SNMPTRAP |
| bgp | 179/tcp | Border Gateway Protocol |
| bgp | 179/udp | Border Gateway Protocol |
| ipx | 213/tcp | IPX |
| ipx | 213/udp | IPX |
| ldap | 389/tcp | Lightweight Directory Access Protocol |
| ldap | 389/udp | Lightweight Directory Access Protocol |
| timbuktu | 407/tcp | Timbuktu |
| timbuktu | 407/udp | Timbuktu |
| https | 443/tcp | http protocol over TLS/SSL |
| https | 443/udp | http protocol over TLS/SSL |
| microsoft-ds | 445/tcp | Microsoft-DS |
| microsoft-ds | 445/udp | Microsoft-DS |
| isakmp | 500/udp | isakmp |
| syslog | 514/udp | syslog |
| ldaps | 636/tcp | ldap protocol over TLS/SSL |
| ldaps | 636/udp | ldap protocol over TLS/SSL |