Check Point's SecuRemote topology download — the single most reliable fingerprint for a Check Point gateway.
IANA registered 264 for BGMP, the Border Gateway Multicast Protocol of RFC 3913, which was never deployed. The port's real occupant is Check Point's FW1_topo service: remote-access VPN clients connect here to fetch the gateway's encryption domain and network topology before building a tunnel. Because that exchange historically answered unauthenticated queries, 264 became a standard reconnaissance target — a scanner that gets a response can often read the firewall's hostname and internal network list. Seeing 264 open on a public IP identifies the vendor immediately.
Do not expose
The topology service has leaked gateway hostnames and internal network ranges to unauthenticated clients; if remote-access VPN does not need it, Check Point lets you disable the implied rule that opens it.
$ nmap -sV -p 264 TARGETSeen this on your network? Beige Box scans your Wi-Fi and shows every open port on every device — and its Ports tool links straight back here.
Get Beige Box →also available as JSON · Markdown
Corrections or a missing port? Reply @rimrocksystems.