WHATPORT(264) whatport.net WHATPORT(264)
264

Check Point FW1 topology (IANA: BGMP)

Check Point's SecuRemote topology download — the single most reliable fingerprint for a Check Point gateway.

TCP IANA: bgmp

Description

IANA registered 264 for BGMP, the Border Gateway Multicast Protocol of RFC 3913, which was never deployed. The port's real occupant is Check Point's FW1_topo service: remote-access VPN clients connect here to fetch the gateway's encryption domain and network topology before building a tunnel. Because that exchange historically answered unauthenticated queries, 264 became a standard reconnaissance target — a scanner that gets a response can often read the firewall's hostname and internal network list. Seeing 264 open on a public IP identifies the vendor immediately.

Exposed to the internet?

Do not expose

The topology service has leaked gateway hostnames and internal network ranges to unauthenticated clients; if remote-access VPN does not need it, Check Point lets you disable the implied rule that opens it.

Check it yourself

$ nmap -sV -p 264 TARGET

See also

Seen this on your network? Beige Box scans your Wi-Fi and shows every open port on every device — and its Ports tool links straight back here.

Get Beige Box →

also available as JSON · Markdown

Corrections or a missing port? Reply @rimrocksystems.