<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: &amp;quot;Not a valid FQDN or IP address&amp;quot; when changing FQDN of SAML portal in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-Not-a-valid-FQDN-or-IP-address-quot-when-changing-FQDN-of/m-p/171510#M31098</link>
    <description>&lt;P&gt;For SAML to work properly, the DNS names for the SAML portal must be resolvable by your clients.&lt;BR /&gt;This generally means the DNS name needs to be globally resolvable.&lt;BR /&gt;In this case, I believe the management is doing the name resolution check.&lt;/P&gt;</description>
    <pubDate>Tue, 14 Feb 2023 22:06:13 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-02-14T22:06:13Z</dc:date>
    <item>
      <title>"Not a valid FQDN or IP address" when changing FQDN of SAML portal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-Not-a-valid-FQDN-or-IP-address-quot-when-changing-FQDN-of/m-p/171494#M31092</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;In gateway settings -&amp;gt; Remote Access clients -&amp;gt; SAML Portal, when I change the SAML portal URL from &lt;A href="https://workingfqdn/saml-vpn" target="_blank"&gt;https://workingdomain.co.nz/saml-vpn&lt;/A&gt;&amp;nbsp;to &lt;A href="https://notworkingfqdn/saml-vpn" target="_blank"&gt;https://not-workingdomain.com/saml-vpn&lt;/A&gt;&amp;nbsp;I get the error "not a valid FQDN or IP address" even though workingdomain.co.nz and not-workingdomain.com both point to the same IP address.&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. what is doing the domain lookup for this, is it the gateway?&lt;/P&gt;&lt;P&gt;2. other than forward lookup fqdn -&amp;gt; ip address, what other "validity" checks are being performed before returning the error?&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 20:01:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-Not-a-valid-FQDN-or-IP-address-quot-when-changing-FQDN-of/m-p/171494#M31092</guid>
      <dc:creator>AK2</dc:creator>
      <dc:date>2023-02-14T20:01:34Z</dc:date>
    </item>
    <item>
      <title>Re: "Not a valid FQDN or IP address" when changing FQDN of SAML portal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-Not-a-valid-FQDN-or-IP-address-quot-when-changing-FQDN-of/m-p/171495#M31093</link>
      <description>&lt;P&gt;I believe for 1) it is gateway and 2) I dont know for sure what other checks are done, but here is what I do know. If I look up my portal on that gateway tab, it shows the following -&amp;gt;&amp;nbsp;&lt;A href="https://172.16.10.205/saml-vpn" target="_blank"&gt;https://172.16.10.205/saml-vpn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;That would be by default, as my main gateway IP is set as 172.16.10.205 and the rest is always there.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you show how yours is set? I would think as long as fqdn resolves to the same IP, there would be no reason for that error.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 20:09:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-Not-a-valid-FQDN-or-IP-address-quot-when-changing-FQDN-of/m-p/171495#M31093</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-14T20:09:43Z</dc:date>
    </item>
    <item>
      <title>Re: "Not a valid FQDN or IP address" when changing FQDN of SAML portal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-Not-a-valid-FQDN-or-IP-address-quot-when-changing-FQDN-of/m-p/171510#M31098</link>
      <description>&lt;P&gt;For SAML to work properly, the DNS names for the SAML portal must be resolvable by your clients.&lt;BR /&gt;This generally means the DNS name needs to be globally resolvable.&lt;BR /&gt;In this case, I believe the management is doing the name resolution check.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 22:06:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-Not-a-valid-FQDN-or-IP-address-quot-when-changing-FQDN-of/m-p/171510#M31098</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-02-14T22:06:13Z</dc:date>
    </item>
    <item>
      <title>Re: "Not a valid FQDN or IP address" when changing FQDN of SAML portal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-Not-a-valid-FQDN-or-IP-address-quot-when-changing-FQDN-of/m-p/171535#M31100</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks. In my case the gateway's external interface is private RFC 1918, NAT-ed behind a public IP (by a separate firewall)&lt;/P&gt;&lt;P&gt;Both workingdomain.co.nz and not-workingdomain.com (which are "made up" public domains) both resolve (using Google DNS 8.8.8.8) to the same public IP address which is then static-NAT-ed to the external address of the gateway.&lt;/P&gt;&lt;P&gt;Both the gateway and the manager are configured to use Google DNS and can successfully resolve both workingdomain.co.nz and not-workingdomain.com to the correct IP (same, public) IP address.&lt;/P&gt;&lt;P&gt;I am wondering what else it checks.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 02:28:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-Not-a-valid-FQDN-or-IP-address-quot-when-changing-FQDN-of/m-p/171535#M31100</guid>
      <dc:creator>AK2</dc:creator>
      <dc:date>2023-02-15T02:28:02Z</dc:date>
    </item>
    <item>
      <title>Re: "Not a valid FQDN or IP address" when changing FQDN of SAML portal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-Not-a-valid-FQDN-or-IP-address-quot-when-changing-FQDN-of/m-p/171536#M31101</link>
      <description>&lt;P&gt;As phoneboy said, SAML fqdns must be resolvable for this to work by the client, otherwise it will not work. My colleague and I did this with 3rd party identity provider in our lab and worked like a charm. Key is really name being resolvable.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 02:59:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-Not-a-valid-FQDN-or-IP-address-quot-when-changing-FQDN-of/m-p/171536#M31101</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-15T02:59:55Z</dc:date>
    </item>
    <item>
      <title>Re: "Not a valid FQDN or IP address" when changing FQDN of SAML portal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-Not-a-valid-FQDN-or-IP-address-quot-when-changing-FQDN-of/m-p/171590#M31113</link>
      <description>&lt;P&gt;Can you provide a screenshot of the error message in question?&lt;BR /&gt;In any case, I recommend opening a TAC case on this if you haven’t already.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 17:11:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-Not-a-valid-FQDN-or-IP-address-quot-when-changing-FQDN-of/m-p/171590#M31113</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-02-15T17:11:11Z</dc:date>
    </item>
    <item>
      <title>Re: "Not a valid FQDN or IP address" when changing FQDN of SAML portal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-Not-a-valid-FQDN-or-IP-address-quot-when-changing-FQDN-of/m-p/171977#M31242</link>
      <description>&lt;P&gt;Hi, Thanks for the help. Unfortunately the actual domains are a bit sensitive so can't post a screenshot. Sorry for delayed reply. I did raise a TAC case and it turns out that there needs to be two "."s in the FQDN.&lt;/P&gt;&lt;P&gt;Won't work (will trigger the error not a valid FQDN):&lt;/P&gt;&lt;P&gt;not-workingdomain.com (only one .)&lt;/P&gt;&lt;P&gt;anything.com (only one .)&lt;/P&gt;&lt;P&gt;Will work:&lt;/P&gt;&lt;P&gt;workingdomain.co.nz (two .) &amp;lt;- this one is misleading, for this case, but it works!&lt;/P&gt;&lt;P&gt;vpn.not-workingdomain.com (two .)&lt;/P&gt;&lt;P&gt;The hint is on page 41 of the Identity Awareness admin guide where it says it has to be "ID.mycompany.com".&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 19 Feb 2023 07:38:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-Not-a-valid-FQDN-or-IP-address-quot-when-changing-FQDN-of/m-p/171977#M31242</guid>
      <dc:creator>AK2</dc:creator>
      <dc:date>2023-02-19T07:38:57Z</dc:date>
    </item>
    <item>
      <title>Re: "Not a valid FQDN or IP address" when changing FQDN of SAML portal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-Not-a-valid-FQDN-or-IP-address-quot-when-changing-FQDN-of/m-p/172099#M31255</link>
      <description>&lt;P&gt;I wonder if .example.com might work?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2023 20:08:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-Not-a-valid-FQDN-or-IP-address-quot-when-changing-FQDN-of/m-p/172099#M31255</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-02-20T20:08:51Z</dc:date>
    </item>
  </channel>
</rss>

