# How to verify that Security Gateway and/or Security Management Server can access Check Point servers?

## Solution

Security Gateways and Security Management Server require access to the Internet (either directly, or via configured proxy) for various Software Blades.

**Important Notes:**

- Make sure the Access Control Policy for Security Gateways does **not** drop / block the connections to the required Check Point servers.

If you disabled the default Implied Rules, then you must follow [sk179346 - Configuring Explicit Rules instead of Implied Rules](https://support.checkpoint.com/results/sk/sk179346).

- Make sure the NAT Policy for Security Gateways does **not** translate the connections to the required Check Point servers.

- In Gaia OS, use the " **`curl_cli`**" command.

Notes:
  - To configure proxy settings, do one of these:
    - Configure the proxy server locally in Gaia OS settings as described in the _[Gaia Administration Guide](https://support.checkpoint.com/product/73#f[commonsource]=C.%20Documentation)_ for your version > chapter "System Management" > section "Proxy".
    - Configure the proxy server in SmartConsole:
      - In Menu > option "Global properties" > page "Proxy" (applies to all objects).
      - In the Security Gateway / Management Server object > section "Network Management" > page "Proxy" (overrides the global proxy configuration).
  - Refer to [sk110779 - "curl: (900) servercert: Error - server certificate validation failed!" when running "curl_cli" command](https://support.checkpoint.com/results/sk/sk110779).
  - For each of the **`curl_cli`** commands, add the option **`--cacert $CPDIR/conf/ca-bundle.crt`** to prevent the issue in [sk110779](https://support.checkpoint.com/results/sk/sk110779).
- In Gaia Embedded OS (all versions), use the " **`wget`**" command.

Notes:
  - To configure proxy settings, do one of these:
    - In the Locally Managed mode and Centrally Managed mode - configure the proxy server locally in Gaia OS settings as described in the _Spark Firewall Locally Managed Administration Guide_ for your version ( [R81.10.x](https://support.checkpoint.com/results/sk/sk179615), [R80.20.x](https://support.checkpoint.com/results/sk/sk165734), [R77.20.x](https://support.checkpoint.com/results/sk/sk97766)) > chapter "Managing the Device" > section "Configuring the Proxy Server".

- In the Centrally Managed mode only - configure the proxy server in SmartConsole > the Security Gateway object > section "Topology" > page "Proxy" (overrides the proxy settings in SmartConsole > Global Properties > page "Proxy").
- If you configured an IPv6 address on an external interface on your Security Gateway / Security Management Server, then the Access Control policy must also allow the IPv6 connections to domains listed below.

- All the domains below are part of the new Updatable object "Check Point Services".

For more information about Updatable objects, see [sk131852](https://support.checkpoint.com/results/sk/sk131852).

- You can also check and subscribe to updates on the [Services status page](https://status.checkpoint.com/).

The table below lists the relevant connectivity tests.

Enter the string to filter this table:

|     |     |     |     |     |
| --- | --- | --- | --- | --- |
| Hostname | Protocol | From | Used For (Version) | Verifying Connectivity (Run command listed below. You will get a response if connectivity is OK.) |
| `cws.checkpoint.com` | http | Security Gateway,<br>Security Management Server,<br>SMB Gateways | Social Media Widget Detection | `curl_cli [--proxy <IP_or_HostName:Port>] -v http://cws.checkpoint.com/APPI/SystemStatus/type/short` |
| URL Filtering Cloud Categorization | `curl_cli [--proxy <IP_or_HostName:Port>] -v http://cws.checkpoint.com/URLF/SystemStatus/type/short` |
| Virus Detection | `curl_cli [--proxy <IP_or_HostName:Port>] -v http://cws.checkpoint.com/AntiVirus/SystemStatus/type/short` |
| Bot Detection | `curl_cli [--proxy <IP_or_HostName:Port>] -v http://cws.checkpoint.com/Malware/SystemStatus/type/short` |
| `updates.checkpoint.com` | https<br>http | Security Gateway,<br>Security Management Server,<br>Spark Firewall | IPS Updates,<br>Updatable Object (R80.20 and higher, on Security Gateway and Security Management) | `curl_cli [--proxy <IP_or_HostName:Port>] -v -k https://updates.checkpoint.com/WebService/Monitor` |
| `crl.godaddy.com` | https<br>http | Security Gateway,<br>Security Management Server | Update Service uses it for revocation | `curl_cli [--proxy <IP_or_HostName:Port>] -v -k https://crl.godaddy.com/` |
| `crl.globalsign.com` | http | Security Gateway,<br>Security Management Server | CRL that updates service certificate uses | `curl_cli -v http://crl.globalsign.com/` |
| `dl3.checkpoint.com` | https | Security Gateway,<br>Security Management Server | Download Service Updates<br>Updatable Object (R80.20 and higher, on Security Gateway and Security Management) | `curl_cli [--proxy <IP_or_HostName:Port>] -v -k https://dl3.checkpoint.com` |
| `usercenter.checkpoint.com` | https | Security Gateway,<br>Security Management Server | Contract Entitlement for IPS, Traditional Anti-Virus, Legacy URL Filtering | `curl_cli [--proxy <IP_or_HostName:Port>] -v -k https://usercenter.checkpoint.com/usercenter/services/productcoverageservice` |
| `usercenter.checkpoint.com` | https | Security Gateway,<br>Security Management Server | Software Blades Manager Service | `curl_cli [--proxy <IP_or_HostName:Port>] -v --cacert $CPDIR/conf/ca-bundle.crt https://usercenter.checkpoint.com/usercenter/services/BladesManagerService` |
| `resolver1.chkp.ctmail.com`<br>`resolver2.chkp.ctmail.com`<br>`resolver3.chkp.ctmail.com`<br>`resolver4.chkp.ctmail.com`<br>`resolver5.chkp.ctmail.com` | http | Security Gateway | Suspicious Mail Outbreaks | `curl_cli [--proxy <IP_or_HostName:Port>] -v http://resolver1.chkp.ctmail.com` |
| `download.ctmail.com` | http | Security Gateway,<br>Security Management Server | Anti-Spam | `curl_cli [--proxy <IP_or_HostName:Port>] -v http://download.ctmail.com` |
| `te.checkpoint.com` | https | Security Gateway | Threat Emulation | `curl_cli [--proxy <IP_or_HostName:Port>] -v -k https://te.checkpoint.com/tecloud/Ping` |
| `teadv.checkpoint.com` | https<br>http | Security Gateway | Threat Emulation | `curl_cli [--proxy <IP_or_HostName:Port>] -v http://teadv.checkpoint.com/version.txt` |
| `threat-emulation.checkpoint.com` | https | Security Gateway | Threat Emulation | `curl_cli [--proxy <IP_or_HostName:Port>] -v https://threat-emulation.checkpoint.com/tecloud/Ping` |
| `ptcs.checkpoint.com`<br>`ptcd.checkpoint.com` | https | Security Gateway | Private ThreatCloud (PTC) Updates | `curl_cli [--proxy <IP_or_HostName:Port>] -v https://ptcs.checkpoint.com`<br>`curl_cli [--proxy <IP_or_HostName:Port>] -v https://ptcd.checkpoint.com` |
| `kav8.zonealarm.com` | http | Security Gateway | Archive scanning,<br>Deep inspection | `curl_cli [--proxy <IP_or_HostName:Port>] -v http://kav8.zonealarm.com/version.txt` |
| `kav8.checkpoint.com` | https<br>http | Security Gateway<br>Endpoint Security Management | Traditional Anti-Virus,<br>Endpoint Security Management pulling Anti-Malware updates | `curl_cli [--proxy <IP_or_HostName:Port>] -v http://kav8.checkpoint.com/version.txt` |
| `avupdates.checkpoint.com` | https<br>http | Security Gateway | Traditional Anti-Virus,<br>Legacy URL Filtering | `curl_cli [--proxy <IP_or_HostName:Port>] -v http://avupdates.checkpoint.com/UrlList.txt` |
| `sigcheck.checkpoint.com` | http | Security Gateway,<br>Security Management Server | Download of signature updates for Traditional Anti-Virus, Legacy URL Filtering, UTM-1 Edge devices | `curl_cli [--proxy <IP_or_HostName:Port>] -v http://sigcheck.checkpoint.com/Siglist2.txt` |
| `secureupdates.checkpoint.com` | http | General updates server for Check Point gateways | Manage Security Gateways | `curl_cli [--proxy <IP_or_HostName:Port>] -I http://secureupdates.checkpoint.com/IP-list/100k.txt` |
| `productcoverage.checkpoint.com` | https | Security Gateway,<br>Security Management Server | Makes sure the contracts are up-to-date | `curl_cli [--proxy <IP_or_HostName:Port>] -v https://productcoverage.checkpoint.com/productcoverageservice` |
| `sc1.checkpoint.com`<br>`sc2.checkpoint.com`<br>`sc3.checkpoint.com`<br>`sc4.checkpoint.com`<br>`sc5.checkpoint.com` | https | Security Gateway,<br>Security Management Server,<br>SmartConsole,<br>SmartDashboard | Download of icons and screenshots from Check Point media storage servers (e.g., [Check Point AppWiki](http://appwiki.checkpoint.com/)) | `curl_cli [--proxy <IP_or_HostName:Port>] -v https://sc1.checkpoint.com/sc/images/checkmark.gif`<br>`curl_cli [--proxy <IP_or_HostName:Port>] -v https://sc1.checkpoint.com/za/images/facetime/large_png/60342479_lrg.png`<br>`curl_cli [--proxy <IP_or_HostName:Port>] -v https://sc1.checkpoint.com/za/images/facetime/large_png/60096017_lrg.png` |
| `push.checkpoint.com` | https | Mobile Access Gateway | Push Notifications for incoming e-mails and meeting requests on handheld devices, while the Capsule Workspace Mail app is in the background | `curl [--proxy <IP_or_HostName:Port>] -v -k https://push.checkpoint.com/push/ping` |
| `downloads.checkpoint.com` | http | Mobile Access Gateway,<br>Security Management Server | Download of Endpoint Compliance Updates (Endpoint Security On Demand (ESOD) database):<br> | `curl_cli [--proxy <IP_or_HostName:Port>] -v http://downloads.checkpoint.com` |
| `productservices.checkpoint.com` | https | Security Gateway,<br>Security Management Server | Next Generation Licensing (Entitlement / Licensing Updates) | `curl_cli [--proxy <IP_or_HostName:Port>] -v http://productservices.checkpoint.com` |
| `diag-services.checkpoint.com` | https | Security Gateway,<br>Security Management Server | Core Dump File uploader (Authentication / Upload backend) | `curl [--proxy <IP_or_HostName:Port>] -v -k https://diag-services.checkpoint.com` |
| `mercury.ts.checkpoint.com`<br>`fairfax.ott.checkpoint.com`<br>`ftp-proxy.checkpoint.com` | https | Security Gateway,<br>Security Management Server | File uploader for CPinfo, CP_Uploader, CPSizeMe (to a server in USA, Canada, Israel) | `curl [--proxy <IP_or_HostName:Port>] -v -k mercury.ts.checkpoint.com`<br>`curl [--proxy <IP_or_HostName:Port>] -v -k fairfax.ott.checkpoint.com`<br>`curl [--proxy <IP_or_HostName:Port>] -v -k ftp-proxy.checkpoint.com` |
| `rep.checkpoint.com` | https | Security Gateway,<br>Security Management Server, Cloud Firewall agents for Kubernetes workloads | Reputation service | `curl_cli [--proxy <IP_or_HostName:Port>] -v -k https://rep.checkpoint.com -X POST -w '\nHTTP Status: %{http_code}\n'` |
| `<Service-Identifier>.maas.checkpoint.com` | https | Smart-1 Cloud service | On-premises Management Server and On-premises Security Gateways connect to the Smart-1 Cloud service | To test connectivity with Smart-1 Cloud deployments in Europe:<br>`curl_cli [--proxy <IP_or_HostName:Port>] -v cloudinfra-gw.portal.checkpoint.com`<br>To test connectivity with Smart-1 Cloud deployments in the United States:<br>`curl_cli [--proxy <IP_or_HostName:Port>] -v cloudinfra-gw-us.portal.checkpoint.com`<br>To test connectivity with Smart-1 Cloud deployments in the APAC:<br>`curl_cli [--proxy <IP_or_HostName:Port>] -v cloudinfra-gw.ap.portal.checkpoint.com` |
| `api-cpx.dome9.com`<br>`api.dome9.com`<br>`api-cpx.eu1.dome9.com`<br>`api.eu1.dome9.com`<br>`api-cpx.ap2.dome9.com`<br>`api.ap2.dome9.com`<br>`api-cpx.cace1.dome9.com`<br>`api.cace1.dome9.com`<br>`api-cpx.ap3.dome9.com`<br>`api.ap3.dome9.com`<br>`api-cpx.ap1.dome9.com`<br>`api.ap1.dome9.com` | https | Cloud Firewall agents for Kubernetes workloads | Cloud Firewall services | `curl_cli [--proxy <IP_or_HostName:Port>] -v -k https://api-cpx.dome9.com/namespaces -X POST`<br>`curl_cli [--proxy <IP_or_HostName:Port>] -v -k https://api.dome9.com -X POST -w '\nHTTP Status: %{http_code}\n' -o /dev/null` |
| `shiftleft.portal.checkpoint.com`<br>`shiftleft-prod-bucket.sg.iaas.checkpoint.com`<br>`us-gw.sg.iaas.checkpoint.com`<br>`eu-gw.sg.iaas.checkpoint.com`<br>`au-gw.sg.iaas.checkpoint.com`<br>`ca-gw.sg.iaas.checkpoint.com`<br>`in-gw.sg.iaas.checkpoint.com`<br>`sg-gw.sg.iaas.checkpoint.com` | https | Cloud Firewall agents for Kubernetes workloads | Vulnerability scanner services | `curl_cli [--proxy <IP_or_HostName:Port>] -v -k https://shiftleft.portal.checkpoint.com` |
| `*.amazontrust.com`<br>`ocsp.e2m02.amazontrust.com`<br>`ocsp.e2m03.amazontrust.com`<br>`ocsp.e2m04.amazontrust.com`<br>`crt.e2m02.amazontrust.com`<br>`crt.e2m03.amazontrust.com`<br>`crt.e2m04.amazontrust.com`<br>`crl.e2m02.amazontrust.com`<br>`crl.e2m03.amazontrust.com`<br>`crl.e2m04.amazontrust.com`<br>`ocsp.rootca1.amazontrust.com`<br>`ocsp.rootca2.amazontrust.com`<br>`ocsp.rootca3.amazontrust.com`<br>`ocsp.rootca4.amazontrust.com`<br>`ocsp.rootg2.amazontrust.com`<br>`crt.rootca1.amazontrust.com`<br>`crt.rootca2.amazontrust.com`<br>`crt.rootca3.amazontrust.com`<br>`crt.rootca4.amazontrust.com`<br>`crt.rootg2.amazontrust.com`<br>`crl.rootca1.amazontrust.com`<br>`crl.rootca2.amazontrust.com`<br>`crl.rootca3.amazontrust.com`<br>`crl.rootca4.amazontrust.com`<br>`crl.rootg2.amazontrust.com` | http | Security Gateway,<br>Security Management Server | Services in Check Point Portal (formerly, Infinity Portal) | `curl_cli [--proxy <IP_or_HostName:Port>] -v -k <Specific FQDN>` |
| `dns.google.com` | icmp | Spark Firewall | Probing | 1. In WebUI, go to "Device" view > "System" section > "Tools" page.<br>2. Use the Ping tool. |
| `dns.cloudflare.com` | icmp | Spark Firewall | Probing | 1. In WebUI, go to "Device" view > "System" section > "Tools" page.<br>2. Use the Ping tool. |
| `dns.opendns.com` | icmp | Spark Firewall | Probing | 1. In WebUI, go to "Device" view > "System" section > "Tools" page.<br>2. Use the Ping tool. |
| `smbcloud-api-gateway.iaas.checkpoint.com` | https | Spark Firewall | Spark Firewall cloud services | `curl_cli [--proxy <IP_or_HostName:Port>] -v -k https://smbcloud-api-gateway.iaas.checkpoint.com/health` |
| `*.spark-management.checkpoint.com` | https | Spark Firewall | Spark Management - Spark Firewall activation | `curl_cli [--proxy <IP_or_HostName:Port>] -v -k <Specific FQDN>` |
| `*.spark-management.checkpoint.com` | http | Spark Firewall | CRL check | `curl_cli [--proxy <IP_or_HostName:Port>] -v -k <Specific FQDN>` |
| `*.portal.checkpoint.com`<br>`*.in.portal.checkpoint.com` | https | Spark Firewall | Services in Check Point Portal (formerly, Infinity Portal) | `curl_cli [--proxy <IP_or_HostName:Port>] -v -k <Specific FQDN>` |
| `*.iaas.checkpoint.com` | https | Spark Firewall | Spark Firewall activation service | `curl_cli [--proxy <IP_or_HostName:Port>] -v -k <Specific FQDN>` |
| `*.<Region>.ddnsbox.com` | TCP port 53 | Spark Firewall | Dynamic DNS (DDNS) | `curl_cli [--proxy <IP_or_HostName:Port>] -v -k <Specific FQDN>` |
| `zerotouch.checkpoint.com` | https | Spark Firewall | Zero Touch deployment | `test zero-touch-request` |
| `smbmgmtservice.checkpoint.com` | https | Spark Firewall | SMP Portal deployment - **obsoleted** by Spark Management | `smp_connectivity_test smbmgmtservice.checkpoint.com` |
| See [sk179105](https://support.checkpoint.com/results/sk/sk179105).<br>Note - These domains are part of the " _Check Point Services_" Updatable object. | https | Check Point Portal (formerly, Infinity Portal) | Services in Check Point Portal (formerly, Infinity Portal) | `curl_cli [--proxy <IP_or_HostName:Port>] -v -k <URL>` |

**Additional Notes:**

- Specific IP addresses for the servers are not provided because they vary by region and are subject to change.

- There are some Check Point Services / Software Blades that require Proxy configuration on top of the Proxy global property configured in the object of your Security Management Server / Domain Management Server, so that connections to `sigcheck.checkpoint.com` will be able to pass through your Proxy server.

Show / Hide Examples from R7X SmartDashboard

Note: Check if you have one those blades enabled and configure proxy settings for each of them.

- Endpoint Compliance:

> 1. Go to the "Mobile Access" tab
    >     2. Expand the "Endpoint Security On Demand"
    >     3. Click on the "Endpoint Compliance Updates"
    >     4. In the "Automatic Update" section, click on the "Configure..." button
    >     5. Go to the "Proxy" tab
    >
    > Example:
    >
    >

- Legacy URL Filtering:

> 1. Go to the "Application & URL Filtering" tab
    >     2. Expand the "Legacy URL Filtering"
    >     3. Click on the "Legacy URL Filtering Policy"
    >     4. Click on the "Automatic updates" link
    >     5. Go to the "Proxy" tab
    >
    > Example:
    >
    >

- Traditional Anti-Virus and UTM-1 Edge devices:

> 1. Go to the "Threat Prevention" tab
    >     2. Expand the "Traditional Anti-Virus"
    >     3. Click on the "Database Updates"
    >     4. In the "Automatic Update" section, click on the "Configure..." button
    >     5. Go to the "Proxy" tab
    >
    > Example:
    >
    >

**Revision History**

|     |     |
| --- | --- |
| Date | Description |
| 18 May 2025 | Added servers for CPinfo, CP_Uploader, CPSizeMe |
| 10 Jan 2025 | Added the notes about Access Control policy and NAT policy |
| 23 Oct 2024 | Added _<Service-Identifier>.maas.checkpoint.com_ |
| 14 Apr 2024 | Updated the list for Spark Firewall |
| 01 Nov 2023 | - Added reference to Proxy configuration in the applicable Administration Guides<br>- Added Check Point Portal services (sk179105) |
| 29 May 2017 | Added information about Proxy configuration on top of the Proxy global property configured in the object of Security Management Server / Domain Management Server |
| 25 Apr 2017 | Added _http://downloads.checkpoint.com_ |
| 16 Feb 2017 | Added "Revision History" section |
| 02 Mar 2017 | Added _teadv.checkpoint.com_ |
