<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Gaia Portal (WebUI) over HTTP in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-Portal-WebUI-over-HTTP/m-p/218671#M41750</link>
    <description>&lt;P&gt;Is this related to redirect part though? 80 -&amp;gt; 443?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Tue, 25 Jun 2024 16:43:47 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-06-25T16:43:47Z</dc:date>
    <item>
      <title>Gaia Portal (WebUI) over HTTP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-Portal-WebUI-over-HTTP/m-p/218569#M41724</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;I am currently going through an ISO/SOC2 recertification audit and the auditors have asked to see the configuration on the gateway that only allows access to the WebUI over tcp/443(HTTPS) and doesnt allow access on tcp/80(HTTP) however I cannot find where this is configured.&lt;/P&gt;&lt;P&gt;Doing some investigation and opening a case with TAC, I have confirmed that the gateway does infact allow traffic on port 80 however there is a kernel level redirect which redirects the traffic to HTTPS. I was able to find a similar post(&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Gaia-Web-GUI-http-to-https-redirection/td-p/184801" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Gaia-Web-GUI-http-to-https-redirection/td-p/184801&lt;/A&gt;) in regards to the HTTPS redirect, however I cannot find anything in the R81.20 Admin Guide or any CheckPoint docs that mentions this being configured by default.&lt;/P&gt;&lt;P&gt;TAC suggested that I follow&amp;nbsp;sk165937 to disable the connection to gateway on TCP Port 80 and add a SAM rule to block port 80 so it shows a drop in the logs but this seems excessive seeing as there is already the kernel redirect and all I need to do is provide documentation that it is a default configuration.&lt;/P&gt;&lt;P&gt;If anyone has any doc that would help me out, it would be appreciated!&lt;/P&gt;&lt;P&gt;Thanks!&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2024 01:46:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-Portal-WebUI-over-HTTP/m-p/218569#M41724</guid>
      <dc:creator>kevin-p</dc:creator>
      <dc:date>2024-06-25T01:46:28Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia Portal (WebUI) over HTTP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-Portal-WebUI-over-HTTP/m-p/218617#M41728</link>
      <description>&lt;P&gt;Personally, I had never heard or seen document that states that, its been that way for who knows how long. Personally, if I were you, I would ask your SE to check on it internally, if one even exists.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2024 12:46:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-Portal-WebUI-over-HTTP/m-p/218617#M41728</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-25T12:46:39Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia Portal (WebUI) over HTTP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-Portal-WebUI-over-HTTP/m-p/218668#M41749</link>
      <description>&lt;P&gt;The feature that does this redirect is called Multiportal and has been there since R75.&lt;BR /&gt;I believe the documentation you are looking for that it's a default is:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk66030" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk66030&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2024 16:36:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-Portal-WebUI-over-HTTP/m-p/218668#M41749</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-06-25T16:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia Portal (WebUI) over HTTP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-Portal-WebUI-over-HTTP/m-p/218671#M41750</link>
      <description>&lt;P&gt;Is this related to redirect part though? 80 -&amp;gt; 443?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2024 16:43:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-Portal-WebUI-over-HTTP/m-p/218671#M41750</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-25T16:43:47Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia Portal (WebUI) over HTTP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-Portal-WebUI-over-HTTP/m-p/218678#M41751</link>
      <description>&lt;P&gt;Yes, this is part of what Multiportal does.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2024 17:09:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-Portal-WebUI-over-HTTP/m-p/218678#M41751</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-06-25T17:09:59Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia Portal (WebUI) over HTTP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-Portal-WebUI-over-HTTP/m-p/218679#M41752</link>
      <description>&lt;P&gt;I get that part, but I think this port 80 -&amp;gt; port 443 redirect used to happen way before multiportal came along?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2024 17:24:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-Portal-WebUI-over-HTTP/m-p/218679#M41752</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-25T17:24:06Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia Portal (WebUI) over HTTP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-Portal-WebUI-over-HTTP/m-p/218690#M41753</link>
      <description>&lt;P&gt;I believe so, yes.&lt;BR /&gt;Previously, I believe it was done as part of the underlying Apache configuration.&lt;BR /&gt;When Multiportal was introduced in R75, it was moved there.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2024 18:39:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-Portal-WebUI-over-HTTP/m-p/218690#M41753</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-06-25T18:39:16Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia Portal (WebUI) over HTTP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-Portal-WebUI-over-HTTP/m-p/218691#M41754</link>
      <description>&lt;P&gt;Ah, good ol' Apache &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Now it all makes sense.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2024 18:41:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-Portal-WebUI-over-HTTP/m-p/218691#M41754</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-25T18:41:11Z</dc:date>
    </item>
  </channel>
</rss>

