TCP 264
Synopsis
- TCP port 264 is used by Check Point FireWall-1/VPN-1 for the fw1_topo service, which distributes topology information between the SmartCenter (management) server, gateways, and SecuRemote/SecureClient VPN clients.
- In the field, gateways often expose 264/tcp so remote clients can fetch encryption domain/topology data during VPN configuration.
- This port is frequently scanned to fingerprint Check Point devices; older or misconfigured deployments could leak internal network topology, making it a reconnaissance target.
- No other mainstream, widely deployed software is known to use TCP/264.
Observed activity
Last 30 days
Detailed chart