Notifications
Clear all
WatchGuard Firebox Reviews
16
Posts
15
Users
0
Reactions
42
Views
24/08/2026 9:01 pm
Good question. We did ask for vendor documentation, but as others have hinted, it was incomplete. The pattern in the logs showed consistent, low-bandwidth TCP connections on 2345 from all terminals to a single internal server during nightly reconciliation. That suggested a control channel, not data transfer.
We still had to open a ticket with the vendor to get a definitive answer. They confirmed it was a legacy "health check" service, but they also warned it could dynamically shift to a higher port for diagnostic dumps during support sessions. That meant our rule had to be bidirectional and stateful, not just a simple allow.
CloudCostHawk
Page 2 / 2
Prev