sk182032 - SAML login in SmartConsole fails when Gaia Portal on the Management Server runs on a different port than 443
SAML login in SmartConsole fails when Gaia Portal on the Management Server runs on a different port than 443
Product: Multi-Domain Security Management, Security Management
Version: R81.20
OS: Gaia
Last Modified: 2025-09-10
Symptoms
- SAML login in SmartConsole fails - a web browser opens the SAML authentication page, but the login times out.
Cause
An administrator configured the Gaia Portal on the Management Server to work on a different port than the default TCP port 443. For example, on an on-premises Endpoint Security Server, the official instructions are to change the Gaia Portal to work on the TCP port 4434.
By design, SAML authentication for SmartConsole requires Gaia Portal on the Management Server to work on the TCP port 443.
Solution
This problem was fixed. The fix is included in:
- Check Point Quantum R82
- R81.20 SmartConsole starting from Build 671
Contact Check Point Support to get a Hotfix for this issue - improved SmartConsole.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.
For faster resolution and verification, collect the CPinfo file from the Management Server involved in the case.
Hotfix installation instructions:
- Uninstall the current SmartConsole.
- Install the new SmartConsole.
How to log in:
In the SmartConsole login window:
- In the top field, click the leftmost icon and select Identity Provider.
- In the bottom field, enter the IP address of the Management Server with the port, on which the Gaia Portal works on the Management Server.
Example:
If the IP address of the Management Server is 192.168.22.55, and the Gaia Portal on the Management Server works on the TCP 4434, then in the SmartConsole login window, you must enter:
192.168.22.55:4434
How to get the port, on which the Gaia Portal works on the Management Server:
- Connect to the command line on the Management Server.
- Login to the Expert mode.
- Run one of these commands:
dbget httpd:ssl_port
Example output:
[Expert@MyMgmt:0]# dbget httpd:ssl_port 4434 [Expert@MyMgmt:0]#
api status
Example output - refer to the field " APACHE Gaia Port":
[Expert@MyMgmt:0]# api status API Settings: --------------------- Accessibility: Require local Automatic Start: Enabled Processes: Name State PID More Information ------------------------------------------------- API Started 15645 CPM Started 15645 Check Point Security Management Server is running and ready FWM Started 15184 APACHE Started 16380 Port Details: ------------------- JETTY Internal Port: 51302 JETTY Documentation Internal Port: 57941 APACHE Gaia Port: 4434 Profile: ------------------- Machine profile: Small Medium env resources profile CPM heap size: 1280m Apache port retrieved from: dbget http:ssl_port -------------------------------------------- Overall API Status: Started -------------------------------------------- API readiness test SUCCESSFUL. The server is up and ready to receive connections Notes: ------------ To collect troubleshooting data, please run 'api status -s <comment>' [Expert@MyMgmt:0]#
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.