sk181683 - Vulnerability scan on the Security Management Server shows that port 8211 uses weak HMAC algorithms

Vulnerability scan on the Security Management Server shows that port 8211 uses weak HMAC algorithms

Product: Security Management
Version: R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82
OS: Gaia
Last Modified: 2026-01-21

Symptoms

TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA

Port 8211 is used for internal communication between Log Servers for RFL queries.

Solution

This problem was fixed. The fix is included starting from:

Check Point recommends to always upgrade to the Recommended version ( Security Gateway / VSX / Security Management Server / Multi-Domain Security Management Server / SmartConsole).

If you choose not to upgrade, contact Check Point Support to get a Hotfix for your version.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.

For faster resolution and verification, collect these files:

  1. CPinfo file from the Management Server involved in the case.
  2. CPinfo file from the Security Gateway / each Cluster Member involved in the case.

Hotfix installation instructions:

Refer to sk168597 - How to install a Hotfix.

Note: You must install the Hotfix on all the Security Management Servers and Log Servers in order not to break the communication between them over TCP port 8211.

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level: General
Status: Approved by TAC
Date Created: 2023-12-18
Last Modified: 2026-01-21