<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SAML authentication stops working after FW Upgrade / Fresh Install in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/249883#M48801</link>
    <description>&lt;P&gt;we solved that issue with the implementation of new external IP addresses&lt;/P&gt;&lt;P&gt;the problem is that the checkpoint portal already listens on 443&amp;nbsp;&lt;/P&gt;&lt;P&gt;i hadnt to change my idp object. we just used a new and free IP-Address for the saml-vpn and now it works as it should&lt;/P&gt;&lt;P&gt;summary: you need a free ip&lt;/P&gt;</description>
    <pubDate>Tue, 27 May 2025 07:19:40 GMT</pubDate>
    <dc:creator>SWBW_Florian</dc:creator>
    <dc:date>2025-05-27T07:19:40Z</dc:date>
    <item>
      <title>SAML authentication stops working after FW Upgrade / Fresh Install</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/208053#M39414</link>
      <description>&lt;P&gt;Hello Check Mates,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;we have seen on three occasions that the SAML authentication method fails for Client VPN after upgrading to a new Jumbo or reinstalling the gateway from scratch (fresh install).&lt;BR /&gt;Reason for our fresh install was to get rid of the ext3 filesystem which we have on very old and long running firewalls.&lt;BR /&gt;&lt;BR /&gt;since we rely on special custom hotfixes we are stuck to run at R81.10 HFA 110&lt;BR /&gt;&lt;BR /&gt;we get this error message:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Scree01.png" style="width: 495px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24768iF6768A4C08E26FFB/image-dimensions/495x469?v=v2" width="495" height="469" role="button" title="Scree01.png" alt="Scree01.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;x&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen02.png" style="width: 485px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24770iDF15CF330F8A409C/image-dimensions/485x302?v=v2" width="485" height="302" role="button" title="Screen02.png" alt="Screen02.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The error lookalike depends on how the embedded browser is built into the VPN Client, sometimes its the full browser which shows and error, sometimes the browser is embedded into the VPN client itself.&lt;BR /&gt;&lt;BR /&gt;It is very hard to restore the SAML login option.&lt;BR /&gt;Its more like a guessing game to remove the SAML authentication from the gateway, push policy again and adding SAML again. or do many reboot or fail overs. I cannot really say what brings it back ... its more a random success to have the SAML portal working again.&lt;BR /&gt;&lt;BR /&gt;anyone from the audience has seen this before?&lt;BR /&gt;since it struck us 3 times now, i think there is indeed a systemic reason behind it.&lt;BR /&gt;&lt;BR /&gt;after some discoveries i found some interessting hints:&lt;BR /&gt;i see way too little Multiportals running ???&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="50%"&gt;active member with broken SAML portal&amp;nbsp;&lt;/TD&gt;
&lt;TD width="50%"&gt;working member set to standby to check behavior&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="50%"&gt;[Expert@XXXY1:0:ACTIVE]# mpclient list&lt;BR /&gt;DLPSenderPortal&lt;BR /&gt;SecurePlatform&lt;BR /&gt;UserCheck&lt;BR /&gt;nac&lt;BR /&gt;nac_transparent_auth&lt;BR /&gt;saml-vpn&lt;/TD&gt;
&lt;TD width="50%"&gt;[Expert@XXXZ2:0:STANDBY]# mpclient list&lt;BR /&gt;DLPSenderPortal&lt;BR /&gt;ExchangeRegistration&lt;BR /&gt;ReverseProxyClear&lt;BR /&gt;ReverseProxySSL&lt;BR /&gt;SecurePlatform&lt;BR /&gt;UserCheck&lt;BR /&gt;nac&lt;BR /&gt;nac_transparent_auth&lt;BR /&gt;saml-vpn&lt;BR /&gt;sslvpn&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;BR /&gt;when i check if the paths for the SAML portal do exist ... i get disappointed on the newly installed active member they missing, also some directories are not there.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SAML_ERROR2.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24773i5BFAFFF65B3532A3/image-size/large?v=v2&amp;amp;px=999" role="button" title="SAML_ERROR2.PNG" alt="SAML_ERROR2.PNG" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;path is:&amp;nbsp;&lt;BR /&gt;&lt;A href="https://XXXXX.ZZZZ.com/saml-vpn/spPortal/ServiceProviderTabs?realm=vpn_XXXXX_SAML&amp;amp;session=6i7hz9koxbtzm3t" target="_blank"&gt;https://XXXXX.ZZZZ.com/saml-vpn/spPortal/ServiceProviderTabs?realm=vpn_XXXXX_SAML&amp;amp;session=6i7hz9koxbtzm3t&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;[Expert@XXXY1:0:ACTIVE]# find / -name ServiceProvider\*&lt;BR /&gt;/opt/CPSamlPortal/htdocs/spPortal/ServiceProvider&lt;BR /&gt;/opt/CPSamlPortal/phpincs/simplesamlphp/vendor/simplesamlphp/saml2/src/SAML2/Configuration/ServiceProvider.php&lt;BR /&gt;/opt/CPSamlPortal/phpincs/simplesamlphp/vendor/simplesamlphp/saml2/src/SAML2/Configuration/ServiceProviderAware.php&lt;BR /&gt;/opt/CPSamlPortal/spPortal_BEFORE_R81_10_jumbo_hf_main/htdocs/spPortal/ServiceProvider&lt;BR /&gt;/opt/CPSamlPortal/spPortal_BEFORE_R81_10_jumbo_hf_main/phpincs/simplesamlphp/vendor/simplesamlphp/saml2/src/SAML2/Configuration/ServiceProvider.php&lt;BR /&gt;/opt/CPSamlPortal/spPortal_BEFORE_R81_10_jumbo_hf_main/phpincs/simplesamlphp/vendor/simplesamlphp/saml2/src/SAML2/Configuration/ServiceProviderAware.php&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[Expert@XXXZ2:0:STANDBY]# find / -name ServiceProvider\*&lt;BR /&gt;/opt/CPSamlPortal/phpincs/simplesamlphp/vendor/simplesamlphp/saml2/src/SAML2/Configuration/ServiceProvider.php&lt;BR /&gt;/opt/CPSamlPortal/phpincs/simplesamlphp/vendor/simplesamlphp/saml2/src/SAML2/Configuration/ServiceProviderAware.php&lt;BR /&gt;/opt/CPSamlPortal/htdocs/spPortal/ServiceProvider&lt;BR /&gt;/opt/CPSamlPortal/htdocs/spPortal/ServiceProviderTabs&lt;BR /&gt;/opt/CPSamlPortal/spPortal_BEFORE_R81_10_jumbo_hf_main/phpincs/simplesamlphp/vendor/simplesamlphp/saml2/src/SAML2/Configuration/ServiceProvider.php&lt;BR /&gt;/opt/CPSamlPortal/spPortal_BEFORE_R81_10_jumbo_hf_main/phpincs/simplesamlphp/vendor/simplesamlphp/saml2/src/SAML2/Configuration/ServiceProviderAware.php&lt;BR /&gt;/opt/CPSamlPortal/spPortal_BEFORE_R81_10_jumbo_hf_main/htdocs/spPortal/ServiceProvider&lt;BR /&gt;/opt/CPSamlPortal/spPortal_BEFORE_R81_10_jumbo_hf_main/htdocs/spPortal/ServiceProviderTabs&lt;/P&gt;
&lt;P&gt;so it seems the directories and files to run the SAML portal where just not created ... how come?&lt;BR /&gt;TAC has to be involved ...&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;best regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2024 09:42:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/208053#M39414</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2024-03-07T09:42:41Z</dc:date>
    </item>
    <item>
      <title>Re: SAML authentication stops working after FW Upgrade / Fresh Install</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/208123#M39422</link>
      <description>&lt;P&gt;We have experienced the same issue with after we upgraded a AWS GEO cluster from r80.40 to r81. We have a case open with TAC.&lt;/P&gt;&lt;P&gt;The second scenario is for Maestros.. initially it was running on r81.10 take 95 + custom fix for SAML.&lt;/P&gt;&lt;P&gt;After upgrade to take 132 ( which required the custom fix to be uninstalled ) SAML is broken/firewall cannot be accessed using GUI,&amp;nbsp; and there are issues with IPsec tunnel rekey.&amp;nbsp; case is open with TAC for this as well.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2024 16:33:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/208123#M39422</guid>
      <dc:creator>NiladriSarkar</dc:creator>
      <dc:date>2024-03-07T16:33:53Z</dc:date>
    </item>
    <item>
      <title>Re: SAML authentication stops working after FW Upgrade / Fresh Install</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/208125#M39423</link>
      <description>&lt;P&gt;Hello yes understood.&lt;BR /&gt;well TAC is already working on it ... iam confident they will find it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;also check this SK&amp;nbsp;&lt;SPAN&gt;sk181971 but its for Error 400 and not Error 404.&lt;BR /&gt;i suspect i could easily transfer the folders from the working FW to the broken FW. but i want a solid hotfixes and explanation.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2024 16:42:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/208125#M39423</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2024-03-07T16:42:16Z</dc:date>
    </item>
    <item>
      <title>Re: SAML authentication stops working after FW Upgrade / Fresh Install</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/208166#M39424</link>
      <description>&lt;P&gt;Same "Not Found" issue after upgrading to 81.10.&lt;/P&gt;&lt;P&gt;I noticed&amp;nbsp;ServiceProvider changed to&amp;nbsp;ServiceProviderTabs in the URL.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2024 19:20:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/208166#M39424</guid>
      <dc:creator>alannnnnnn</dc:creator>
      <dc:date>2024-03-07T19:20:41Z</dc:date>
    </item>
    <item>
      <title>Re: SAML authentication stops working after FW Upgrade / Fresh Install</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/208372#M39457</link>
      <description>&lt;P&gt;I had same problem after fresh install + take 130&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The fix is: uninstall JHF, install an intermediate JHF (in my case #78), then upgrade to latest JHF&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2024 18:03:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/208372#M39457</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2024-03-11T18:03:12Z</dc:date>
    </item>
    <item>
      <title>Re: SAML authentication stops working after FW Upgrade / Fresh Install</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/208731#M39523</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;TAC mentioned, this issue is known as :&amp;nbsp;PRHF-33044.&lt;BR /&gt;if required they will build a custom fix for you.&lt;BR /&gt;if it affects a R81.20 fresh install is still under investigation!&lt;/P&gt;
&lt;P&gt;best regards&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 10:02:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/208731#M39523</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2024-03-14T10:02:30Z</dc:date>
    </item>
    <item>
      <title>Re: SAML authentication stops working after FW Upgrade / Fresh Install</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/209962#M39782</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;TAC finally solved it ...&lt;BR /&gt;&lt;SPAN&gt;PRHF-33044&amp;nbsp; is the Bug ID&lt;BR /&gt;the issue seemed to start with HFA113, which breaks some files in /opt/CPSaml file structure.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;Fresh install with R81.10&lt;BR /&gt;install HFA in HFA 129 in my case&lt;BR /&gt;Install custom fix provided by TAC for HFA129&lt;BR /&gt;SIC + Policy Push&lt;BR /&gt;and SAML is working again ...&lt;BR /&gt;&lt;BR /&gt;i hope they integrate it into the next GA HFA ...&amp;nbsp;&lt;BR /&gt;otherwise you can do it manually:&lt;BR /&gt;&lt;BR /&gt;backup of both directories&lt;BR /&gt;and copy the good files to the affected FW.&lt;BR /&gt;&lt;SPAN&gt;&lt;SPAN class="ui-provider ee awp awq awr aws awt awu awv aww awx awy awz axa axb axc axd axe axf axg axh axi axj axk axl axm axn axo axp axq axr axs axt axu axv axw"&gt;scp -rp /opt/CPSamlPortal/* admin@XXXXX:/opt/CPSamlPortal&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2024 16:14:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/209962#M39782</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2024-03-28T16:14:14Z</dc:date>
    </item>
    <item>
      <title>Re: SAML authentication stops working after FW Upgrade / Fresh Install</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/209969#M39783</link>
      <description>&lt;P&gt;Yes, I did use "Fresh Install and Upgrade feature" to upgrade from R81.10 take 130&amp;nbsp;to R81.20 and I got the same issue. I had to rollback the upgrade.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2024 19:54:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/209969#M39783</guid>
      <dc:creator>I_Santos</dc:creator>
      <dc:date>2024-03-28T19:54:17Z</dc:date>
    </item>
    <item>
      <title>Re: SAML authentication stops working after FW Upgrade / Fresh Install</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/209972#M39784</link>
      <description>&lt;P&gt;For anyone interested to fix the issue without the custom fix, i suggest the previous workaround:&lt;/P&gt;
&lt;P&gt;-clean install 81.10&lt;/P&gt;
&lt;P&gt;-install JHF 78&lt;/P&gt;
&lt;P&gt;-Install latest JHF&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2024 21:08:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/209972#M39784</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2024-03-28T21:08:05Z</dc:date>
    </item>
    <item>
      <title>Re: SAML authentication stops working after FW Upgrade / Fresh Install</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/218499#M41708</link>
      <description>&lt;P&gt;Hello Thomas,&lt;/P&gt;&lt;P&gt;It seems that we encounter the same issue as yours with the broken SAML Portal (404 on connection attempts).&lt;/P&gt;&lt;P&gt;Our SG cluster is in R81.10 with Hotfix 139.&lt;/P&gt;&lt;P&gt;The current CPSamlPortal structure is as follows:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[Expert@PROXIMA:0]# find / -name ServiceProvider\*
/opt/CPSamlPortal/phpincs/simplesamlphp/vendor/simplesamlphp/saml2/src/SAML2/Configuration/ServiceProvider.php
/opt/CPSamlPortal/phpincs/simplesamlphp/vendor/simplesamlphp/saml2/src/SAML2/Configuration/ServiceProviderAware.php
/opt/CPSamlPortal/spPortal_BEFORE_R81_10_jumbo_hf_main/phpincs/simplesamlphp/vendor/simplesamlphp/saml2/src/SAML2/Configuration/ServiceProvider.php
/opt/CPSamlPortal/spPortal_BEFORE_R81_10_jumbo_hf_main/phpincs/simplesamlphp/vendor/simplesamlphp/saml2/src/SAML2/Configuration/ServiceProviderAware.php
/opt/CPSamlPortal/spPortal_BEFORE_R81_10_jumbo_hf_main/htdocs/spPortal/ServiceProvider
/opt/CPSamlPortal/htdocs/spPortal/ServiceProvider&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As we only have one cluster with the same broken SAML structure, we don't have the possibility to copy the original files to /opt/CPSamlPortal.&lt;/P&gt;&lt;P&gt;Would you (or any generous soul) be willing to send us these files in order to fix the VPN SAML connection?&lt;/P&gt;&lt;P&gt;Thanks &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2024 14:59:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/218499#M41708</guid>
      <dc:creator>TWESTELYNCK</dc:creator>
      <dc:date>2024-06-24T14:59:50Z</dc:date>
    </item>
    <item>
      <title>Re: SAML authentication stops working after FW Upgrade / Fresh Install</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/218504#M41711</link>
      <description>&lt;P&gt;Hello Team,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;better use a BLINK image and go to R81.20 directly!&lt;BR /&gt;then you should have NO issues!&lt;BR /&gt;or downgrade to a hotfix around ~R81.10 HFA 110 and upgrade to to HFA 150 ... then SAML should stay.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;also there is a hotfix for this issue!&lt;BR /&gt;PRHF-33044 &lt;BR /&gt;fw1_wrapper_HOTFIX_R81_10_JHF_T129_937_MAIN_GA_FULL.tar&lt;BR /&gt;but its R81.10&amp;nbsp; HFA120&lt;BR /&gt;-&amp;gt; reach out to TAC, they shall give you a portfix for your version!&lt;BR /&gt;&lt;BR /&gt;i have no more customer running on R81.10, believe or not .. so i cannot send any files.&lt;BR /&gt;what u can also do is to install a GW in a VMware and copy the files as well!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2024 15:35:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/218504#M41711</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2024-06-24T15:35:38Z</dc:date>
    </item>
    <item>
      <title>Re: SAML authentication stops working after FW Upgrade / Fresh Install</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/220958#M42302</link>
      <description>&lt;P&gt;This is the SK in reference for&amp;nbsp;&lt;SPAN&gt;fw1_wrapper_HOTFIX_R81_10_JHF_T129_937_MAIN_GA_FULL.tar&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Documented to be fixed R81.10 jhf 152&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk182128" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk182128&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jul 2024 13:22:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/220958#M42302</guid>
      <dc:creator>SenpaiNoticed_U</dc:creator>
      <dc:date>2024-07-16T13:22:15Z</dc:date>
    </item>
    <item>
      <title>Re: SAML authentication stops working after FW Upgrade / Fresh Install</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/231680#M44681</link>
      <description>&lt;P&gt;Thanks, I had SAML working with R81.20 JHF84 and it's not in JHF89.&amp;nbsp; &amp;nbsp;We aren't even getting to the provider link now from the portal.&amp;nbsp; &amp;nbsp;There were some new changes to SAML and also,&amp;nbsp;&lt;SPAN data-teams="true"&gt;&lt;SPAN class="ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak"&gt;The Security Gateway may fail to resolve external Network Feeds whose URL contains a port number (such as "&lt;A id="menur3j0" class="fui-Link ___1q1shib f2hkw1w f3rmtva f1ewtqcl fyind8e f1k6fduh f1w7gpdv fk6fouc fjoy568 figsok6 f1s184ao f1mk8lai fnbmjn9 f1o700av f13mvf36 f1cmlufx f9n3di6 f1ids18y f1tx3yz7 f1deo86v f1eh06m1 f1iescvh fhgqx19 f1olyrje f1p93eir f1nev41a f1h8hb77 f1lqvz6u f10aw75t fsle3fq f17ae5zn" title="https://example.com:8080/feed.csv" href="https://example.com:8080/feed.csv" target="_blank" rel="noreferrer noopener" aria-label="Link https://example.com:8080/feed.csv"&gt;&lt;I&gt;https://example.com:8080/feed.csv&lt;/I&gt;&lt;/A&gt;". Refer to &lt;A id="menur3j2" class="fui-Link ___1q1shib f2hkw1w f3rmtva f1ewtqcl fyind8e f1k6fduh f1w7gpdv fk6fouc fjoy568 figsok6 f1s184ao f1mk8lai fnbmjn9 f1o700av f13mvf36 f1cmlufx f9n3di6 f1ids18y f1tx3yz7 f1deo86v f1eh06m1 f1iescvh fhgqx19 f1olyrje f1p93eir f1nev41a f1h8hb77 f1lqvz6u f10aw75t fsle3fq f17ae5zn" title="https://support.checkpoint.com/results/sk/sk182684" href="https://support.checkpoint.com/results/sk/sk182684" target="_blank" rel="noreferrer noopener" aria-label="Link sk182684"&gt;sk182684&lt;/A&gt;. &amp;nbsp;maybe it fixed 8080 and broke 8443&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-teams="true"&gt;&lt;SPAN class="ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak"&gt;Update: we fixed this by changing this attritube in the Identity.xml file:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-teams="true"&gt;&lt;SPAN class="ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak"&gt;&amp;nbsp; from "true" to "false"&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="html-attribute-name"&gt;WantAuthnRequestsSigned&lt;/SPAN&gt;="&lt;SPAN class="html-attribute-value"&gt;false&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H1&gt;&lt;SPAN&gt;This page isn’t working&lt;/SPAN&gt;&lt;/H1&gt;
&lt;P&gt;&lt;STRONG&gt;portal.ssl.somedomain.com&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is currently unable to handle this request.&lt;/P&gt;
&lt;DIV id="error-information-popup-container"&gt;
&lt;DIV id="error-information-popup"&gt;
&lt;DIV id="error-information-popup-box"&gt;
&lt;DIV id="error-information-popup-content"&gt;
&lt;DIV class="error-code"&gt;HTTP ERROR 500&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2025 12:18:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/231680#M44681</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2025-03-31T12:18:05Z</dc:date>
    </item>
    <item>
      <title>Re: SAML authentication stops working after FW Upgrade / Fresh Install</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/240077#M46575</link>
      <description>&lt;P&gt;hi there,&lt;/P&gt;&lt;P&gt;i have the same issue at 81.20 on our cluster. i configured the SAML (properly, i hope) but i end with "Not found" as im trying to access it&lt;/P&gt;&lt;P&gt;the link in the adressbar is right so far: mysamldomain.com/spPortal/ServiceProviderTabs?realm=vpn.....&lt;/P&gt;&lt;P&gt;at least the domain is correct, i cant tell anything about the rest built by checkpoint.&lt;/P&gt;&lt;P&gt;Unfortunately i dont have any backup or old stuff laying around to recover some of those maybe missing files.&lt;BR /&gt;Could someone upload a zip with the files in it, at least to compare whats missing?&lt;/P&gt;&lt;P&gt;i also checked the error_log of the portal and get those lines:&lt;/P&gt;&lt;LI-CODE lang="php"&gt;[Mon Jan 27 13:26:39.274902 2025] [php7:notice] [pid 28000] [client 10628] error SamlPolicyReader: IDP_POLICY_DIRECTORY /opt/CPVPNPortal/phpincs/spPortal __DIR__ /opt/CPSamlPortal/phpincs/spPortal, referer: https://mfax.de/webapps/openid/spPortal/ServiceProviderTabs?realm=vpn_RVDev_MFA&amp;amp;session=cvaq33za55jeezt
[Mon Jan 27 13:26:39.275958 2025] [php7:notice] [pid 28000] [client :10628] error allowRealms: 'vpn' is not a SAML realm., referer: https://mfax.de/webapps/openid/spPortal/ServiceProviderTabs?realm=vpn_RVDev_MFA&amp;amp;session=cvaq33za55jeezt&lt;/LI-CODE&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 13:31:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/240077#M46575</guid>
      <dc:creator>SWBW_Florian</dc:creator>
      <dc:date>2025-01-30T13:31:15Z</dc:date>
    </item>
    <item>
      <title>Re: SAML authentication stops working after FW Upgrade / Fresh Install</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/240079#M46576</link>
      <description>&lt;P&gt;Hello Florian,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When authenticating, I´d start with a small browser extension like "SAML-Tracer" for having a look, what is when called and submitted. Also Browsers Development tools can help in fiddling out, where a problem might be. i.e. if a css file is not "accessible", like in my current case... I´m fighting something similar at the moment&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 13:45:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/240079#M46576</guid>
      <dc:creator>Nüüül</dc:creator>
      <dc:date>2025-01-30T13:45:59Z</dc:date>
    </item>
    <item>
      <title>Re: SAML authentication stops working after FW Upgrade / Fresh Install</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/240087#M46580</link>
      <description>&lt;P&gt;hy Nüüül and thanks for your hints.&amp;nbsp;&lt;/P&gt;&lt;P&gt;unfortunately the browser isnt doing a lot but opening and showing that "Not Found" stuff. the login procedure isnt started because of that issue&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 14:42:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/240087#M46580</guid>
      <dc:creator>SWBW_Florian</dc:creator>
      <dc:date>2025-01-30T14:42:07Z</dc:date>
    </item>
    <item>
      <title>Re: SAML authentication stops working after FW Upgrade / Fresh Install</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/245101#M47723</link>
      <description>&lt;P&gt;Hello Floriam&lt;/P&gt;
&lt;P&gt;did u fix the problem ?&amp;nbsp;&lt;BR /&gt;same logs, same&amp;nbsp; issue&lt;/P&gt;
&lt;P&gt;apparently files/direcotry/permission are correct, looking into another working environment&lt;/P&gt;</description>
      <pubDate>Fri, 28 Mar 2025 17:34:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/245101#M47723</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2025-03-28T17:34:08Z</dc:date>
    </item>
    <item>
      <title>Re: SAML authentication stops working after FW Upgrade / Fresh Install</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/245182#M47743</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;No, unfortunately not. its still not working. we asked our Checkpoint-Service for help on that. They think that it propably could come into account that our used IP-Address is already configured elsewhere in the system (and also not the cluster main IP)&lt;/P&gt;&lt;P&gt;So we ordered a new external IP-Adress and try then to forward 443 to this&lt;/P&gt;&lt;P&gt;i will update the thread if were working it out. If you find anything new feel free to post it here as well&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2025 05:29:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/245182#M47743</guid>
      <dc:creator>SWBW_Florian</dc:creator>
      <dc:date>2025-03-31T05:29:17Z</dc:date>
    </item>
    <item>
      <title>Re: SAML authentication stops working after FW Upgrade / Fresh Install</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/245184#M47744</link>
      <description>&lt;P&gt;This is likely not your issue, as it was working previously, but I had the exact same 404 error, my issue was I had the wrong IDP object assigned to my gateway.&amp;nbsp; VPN Clients -&amp;gt; Authentication -&amp;gt; IDP Auth Provider -&amp;gt; Auth Methods -&amp;gt; Identity Provider - Auth Settings.&lt;/P&gt;
&lt;P&gt;My IDP object was pointing to the SAML URL of a different gateway.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2025 06:18:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/245184#M47744</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2025-03-31T06:18:10Z</dc:date>
    </item>
    <item>
      <title>Re: SAML authentication stops working after FW Upgrade / Fresh Install</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/245211#M47748</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;Hi, RE: the identity file, we changed this attribute&amp;nbsp; from true to false.&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN class="html-attribute-name"&gt;WantAuthnRequestsSigned&lt;/SPAN&gt;&lt;SPAN&gt;="&lt;/SPAN&gt;&lt;SPAN class="html-attribute-value"&gt;false&lt;/SPAN&gt;&lt;SPAN&gt;"&amp;nbsp; We still have to have this in place.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2025 12:19:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAML-authentication-stops-working-after-FW-Upgrade-Fresh-Install/m-p/245211#M47748</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2025-03-31T12:19:19Z</dc:date>
    </item>
  </channel>
</rss>

