This might help:
The list below details the common ports used by Check Point Next Generation:
1. TCP 18211 (FW1_ica_push): The Check Point Daemon (CPD) process, running on the FireWall module, listens on TCP port 18211 for certificate creation and for the "push" of the certificate to the FireWall module from the management module.
2. TCP 18210 (FW1_ica_pull): The CPD process, on the management module, is listening on TCP port 18210 for certificates to be "pulled" by a FireWall module from a management module.
3. TCP 18186 (FW1_omi-sic): This TCP port is used for Secure Internal Communications (SIC) between OPSEC certified products and a NG FireWall module.
4. TCP 18191 (CPD): This TCP port is used by the CPD process for communications such as policy installation, certificate revocation, and status queries.
5. TCP 18190 (CPMI): This TCP port is used by the FireWall Management process (FWM) to listen for NG Management Clients attempting to connect to the management module.
6. TCP 18192 (CPD_amon): This TCP port is used by the CPD process FireWall Application Monitoring.
7. TCP 257 (FW1_log): This TCP port is used for logging purposes.