sk182032 - SAML login in SmartConsole fails when Gaia Portal on the Management Server runs on a different port than 443

SAML login in SmartConsole fails when Gaia Portal on the Management Server runs on a different port than 443

Product: Multi-Domain Security Management, Security Management
Version: R81.20
OS: Gaia
Last Modified: 2025-09-10

Symptoms

Cause

An administrator configured the Gaia Portal on the Management Server to work on a different port than the default TCP port 443. For example, on an on-premises Endpoint Security Server, the official instructions are to change the Gaia Portal to work on the TCP port 4434.

By design, SAML authentication for SmartConsole requires Gaia Portal on the Management Server to work on the TCP port 443.

Solution

This problem was fixed. The fix is included in:

Contact Check Point Support to get a Hotfix for this issue - improved SmartConsole.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.

For faster resolution and verification, collect the CPinfo file from the Management Server involved in the case.

Hotfix installation instructions:

  1. Uninstall the current SmartConsole.
  2. Install the new SmartConsole.

How to log in:

In the SmartConsole login window:

  1. In the top field, click the leftmost icon and select Identity Provider.
  2. In the bottom field, enter the IP address of the Management Server with the port, on which the Gaia Portal works on the Management Server.

Example:

If the IP address of the Management Server is 192.168.22.55, and the Gaia Portal on the Management Server works on the TCP 4434, then in the SmartConsole login window, you must enter: 192.168.22.55:4434

How to get the port, on which the Gaia Portal works on the Management Server:

  1. Connect to the command line on the Management Server.
  2. Login to the Expert mode.
  3. Run one of these commands:

Example output:

[Expert@MyMgmt:0]# dbget httpd:ssl_port
4434
[Expert@MyMgmt:0]#

Example output - refer to the field " APACHE Gaia Port":

[Expert@MyMgmt:0]# api status

API Settings:
---------------------
Accessibility:                      Require local
Automatic Start:                    Enabled

Processes:

Name      State     PID       More Information
-------------------------------------------------
API       Started   15645
CPM       Started   15645     Check Point Security Management Server is running and ready
FWM       Started   15184
APACHE    Started   16380

Port Details:
-------------------
JETTY Internal Port:               51302
JETTY Documentation Internal Port: 57941
APACHE Gaia Port:                  4434

Profile:
-------------------
Machine profile:                   Small Medium env resources profile
CPM heap size:                     1280m

                          Apache port retrieved from: dbget http:ssl_port

--------------------------------------------
Overall API Status: Started
--------------------------------------------

API readiness test SUCCESSFUL. The server is up and ready to receive connections

Notes:
------------
To collect troubleshooting data, please run 'api status -s <comment>'

[Expert@MyMgmt:0]#

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.