sk182548 - SAML authentication in Mobile Access Portal does not work in a Maestro Security Group in the VSX mode

SAML authentication in Mobile Access Portal does not work in a Maestro Security Group in the VSX mode

Product: Maestro HyperScale Firewall
Version: R81 (EOS), R81.10 (EOS), R81.20, R82
OS: Gaia
Last Modified: 2025-12-18

Symptoms

Example:

Cause

During the Access Control policy installation, the $SAMLPORTAL_HOME/phpincs/spPortal/idpPolicy.xml file is not updated correctly on the non-SMO Security Group Members.

Solution

This problem was fixed. The fix is included in:

If you choose not to upgrade, follow this workaround procedure:

The shell script cpha_blade_config is responsible for the policy installation task on the non-SMO Security Group Members.

Procedure:

  1. Connect to the command line on the Security Group.

  2. Log in.

  3. If your default shell is Gaia gClish, then go to the Expert mode:

expert

  1. Back up the current cpha_blade_config script:

g_all cp -v $SMODIR/bin/cpha_blade_config{,_BKP}

  1. Edit the current cpha_blade_config script:

vi $SMODIR/bin/cpha_blade_config

  1. Insert the call to the $CPDIR/tmp/.CPprofile.sh script in the required place.

The relevant section before the change:

``...

else

in VSX we can have a lot of processes like these running simultaneously together hence we don't want to bind to only one core

LFETCH_OUTPUT=$FWDIR/bin/fw fetchlocal -d $FWDIR/state/__tmp/FW1 $policy_type 2>&1 >> $LOGFILE 2>&1

fi

...``

The relevant section after the required change:

``...

else

in VSX we can have a lot of processes like these running simultaneously together hence we don't want to bind to only one core

. $CPDIR/tmp/.CPprofile.sh

LFETCH_OUTPUT=$FWDIR/bin/fw fetchlocal -d $FWDIR/state/__tmp/FW1 $policy_type 2>&1 >> $LOGFILE 2>&1

fi

... ``

  1. Save the changes in the file and exit the Vi editor.

  2. Copy the modified script to all Security Group Members:

asg_cp2blades $SMODIR/bin/cpha_blade_config -p

  1. In SmartConsole, install the Access Control policy on the Security Gateway / relevant Virtual System object.

Important - In the Install Policy window, select " Do not use Install Policy Acceleration for all targets".

Example:

  1. On the Security Group, make sure the file idpPolicy.xml is the same on all Security Group Members (SMO and non-SMO):
    1. If this Security Group works in the VSX mode, then go to the context of the relevant Virtual System:

[Expert@HostName-ch0x-0x:0]# vsenv <VSID>

  1. Compare the file idpPolicy.xml on all Security Group Members:

[Expert@HostName-ch0x-0x:<VSID>]# g_allc cat $SAMLPORTAL_HOME/phpincs/spPortal/idpPolicy.xml

Article Properties

Access Level: General
Status: Approved by TAC
Date Created: 2024-08-11
Last Modified: 2025-12-18

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.