List of protocols
- Built-in protocols — updated along with the SSG software version. Installing a new version requires a DPI reboot, which causes traffic interruption.
If needed, they can be supplemented with up-to-date attributes from the VAS Cloud. This is only necessary for complex protocols, but the option is available for all. - Cloud protocols created by VAS Experts — are periodically updated from the VAS Cloud. This ensures that popular applications remain up-to-date as their behavior changes. Description
- Custom (user-defined) protocols — protocols created by users via the GUI using VAS Cloud tools. These have higher priority than those loaded from the VAS Cloud, and within them, IP:PORT takes precedence over IP and CIDR. It is possible to add a protocol based on IP, SNI, or AS. Guide.
- DSL protocols — protocols described in the DSL language and connected to DPI as a separate module, without reinstalling the software or causing traffic interruption. Unlike custom protocols, a DSL protocol is a finite state machine that analyzes the first N packets of a flow against defined conditions (ports, AS numbers, payload bytes, DSL expressions) and determines whether the flow matches the protocol.
DSL protocols are created by VAS Experts specialists upon client request to Technical Support.
| Protocol | ID | DPI version | Protocol group | Protocol type | Update | Description |
|---|---|---|---|---|---|---|
| radpdf | 18104 | 12.2 | Unknown | Built-in | As needed | radpdf operates on port 18104 and facilitates RadPDF for PDF rendering or management over networks. |
| racf | 18136 | 12.2 | Unknown | Built-in | As needed | racf operates on port 18136 and is used by RACF (Resource Access Control Facility) for security and access control. |
| opsec-cvp | 18181 | 12.2 | Unknown | Built-in | As needed | opsec-cvp operates on port 18181 and enables content vectoring protocol services in firewall and proxy integrations. |
| opsec-ufp | 18182 | 12.2 | Unknown | Built-in | As needed | opsec-ufp operates on port 18182 and handles unified firewall policy services in Check Point OPSEC architecture. |
| opsec-sam | 18183 | 12.2 | Unknown | Built-in | As needed | opsec-sam operates on port 18183 and provides session authentication management in OPSEC-based infrastructures. |
| opsec-lea | 18184 | 12.2 | Unknown | Built-in | As needed | opsec-lea operates on port 18184 and supports Log Export API (LEA) in Check Point firewalls for security event logging. |
| opsec-omi | 18185 | 12.2 | Unknown | Built-in | As needed | opsec-omi operates on port 18185 and enables Open Management Interface services for Check Point OPSEC integration. |
| ohsc | 18186 | 12.2 | Unknown | Built-in | As needed | ohsc operates on port 18186 and supports secure communications in OHSC systems used in healthcare or compliance. |
| opsec-ela | 18187 | 12.2 | Unknown | Built-in | As needed | opsec-ela operates on port 18187 and manages encrypted log access in OPSEC event logging systems. |
| checkpoint-rtm | 18241 | 12.2 | Unknown | Built-in | As needed | Check Point Real-Time Monitoring protocol for firewall and security event tracking. |
| iclid | 18242 | 12.2 | Unknown | Built-in | As needed | iclid operates on port 18242 and provides device identification services in ICL enterprise systems. |
| clusterxl | 18243 | 12.2 | Unknown | Built-in | As needed | Check Point ClusterXL protocol for high availability and load-balanced firewall clusters. |
| gv-pf | 18262 | 12.2 | Unknown | Built-in | As needed | gv-pf operates on port 18262 and supports grid visualization or processing features in GV-PF compute frameworks. |
| ac-cluster | 18463 | 12.2 | Unknown | Built-in | As needed | ac-cluster operates on port 18463 and supports node communication in high-performance or distributed AC clustering systems. |
| rds-ib | 18634 | 12.2 | Unknown | Built-in | As needed | rds-ib operates on port 18634 and supports RDS-IB for remote desktop services over InfiniBand. |
| rds-ip | 18635 | 12.2 | Unknown | Built-in | As needed | rds-ip operates on port 18635 and facilitates RDS-IP for remote desktop services over IP networks. |
| ique | 18769 | 12.2 | Unknown | Built-in | As needed | ique operates on port 18769 and supports communication between devices in the iQue handheld console ecosystem. |
| infotos | 18881 | 12.2 | Unknown | Built-in | As needed | infotos operates on port 18881 and supports information transport services in INFOTOS middleware applications. |
| apc-necmp | 18888 | 12.2 | Unknown | Built-in | As needed | apc-necmp operates on port 18888 and supports NECMP (Network Environmental Control Management Protocol) used in APC systems. |
| igrid | 19000 | 12.2 | Unknown | Built-in | As needed | igrid operates on port 19000 and enables communication for interactive grid computing platforms. |
Was this information helpful?