<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Modify 'Return URL' in Identity Provider object for SmartConsole SAML SSO in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Modify-Return-URL-in-Identity-Provider-object-for-SmartConsole/m-p/246728#M41240</link>
    <description>&lt;P&gt;This is for IA (or Remote Access VPN) IdP. I don't think these settings apply to the management server as a SAML SP.&lt;/P&gt;&lt;P&gt;I have submitted a TAC case and will update when (if) I get a solution.&lt;/P&gt;</description>
    <pubDate>Thu, 17 Apr 2025 07:19:16 GMT</pubDate>
    <dc:creator>FtW64</dc:creator>
    <dc:date>2025-04-17T07:19:16Z</dc:date>
    <item>
      <title>Modify 'Return URL' in Identity Provider object for SmartConsole SAML SSO</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Modify-Return-URL-in-Identity-Provider-object-for-SmartConsole/m-p/246662#M41221</link>
      <description>&lt;P&gt;I have successfully setup SmartConsole SAML SSO, using an Identity Provider object in SmartConsole.&lt;/P&gt;&lt;P&gt;When creating this Identity Provider object, the IdP "Return URL" is automatically populated like: "&lt;A href="https://192.168.100.241/" target="_blank"&gt;https://192.168.100.241/&lt;/A&gt;...", where 192.168.100.241 is the IP address of the management server. You cannot edit this value.&lt;/P&gt;&lt;P&gt;I'd like to replace the IP address with the FQDN of the management server, like "&lt;A href="https://sms.mydomain.com/" target="_blank"&gt;https://sms.mydomain.com/&lt;/A&gt;...".&lt;/P&gt;&lt;P&gt;Is this possible? If so, how?&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;-Frank&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2025 13:11:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Modify-Return-URL-in-Identity-Provider-object-for-SmartConsole/m-p/246662#M41221</guid>
      <dc:creator>FtW64</dc:creator>
      <dc:date>2025-04-16T13:11:40Z</dc:date>
    </item>
    <item>
      <title>Re: Modify 'Return URL' in Identity Provider object for SmartConsole SAML SSO</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Modify-Return-URL-in-Identity-Provider-object-for-SmartConsole/m-p/246701#M41225</link>
      <description>&lt;P&gt;I could be mistaken, but the only way I know of possibly be able to do that is if you change what I attached and install policy.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2025 18:59:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Modify-Return-URL-in-Identity-Provider-object-for-SmartConsole/m-p/246701#M41225</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-16T18:59:10Z</dc:date>
    </item>
    <item>
      <title>Re: Modify 'Return URL' in Identity Provider object for SmartConsole SAML SSO</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Modify-Return-URL-in-Identity-Provider-object-for-SmartConsole/m-p/246726#M41239</link>
      <description>&lt;P&gt;if this would work, it only works on standalone installation. management server objects don´t have VPN Portal settings &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;i believe, you will have to change simple-saml config files or something like that. would suggest having TAC involved.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2025 06:49:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Modify-Return-URL-in-Identity-Provider-object-for-SmartConsole/m-p/246726#M41239</guid>
      <dc:creator>Nüüül</dc:creator>
      <dc:date>2025-04-17T06:49:32Z</dc:date>
    </item>
    <item>
      <title>Re: Modify 'Return URL' in Identity Provider object for SmartConsole SAML SSO</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Modify-Return-URL-in-Identity-Provider-object-for-SmartConsole/m-p/246728#M41240</link>
      <description>&lt;P&gt;This is for IA (or Remote Access VPN) IdP. I don't think these settings apply to the management server as a SAML SP.&lt;/P&gt;&lt;P&gt;I have submitted a TAC case and will update when (if) I get a solution.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2025 07:19:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Modify-Return-URL-in-Identity-Provider-object-for-SmartConsole/m-p/246728#M41240</guid>
      <dc:creator>FtW64</dc:creator>
      <dc:date>2025-04-17T07:19:16Z</dc:date>
    </item>
    <item>
      <title>Re: Modify 'Return URL' in Identity Provider object for SmartConsole SAML SSO</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Modify-Return-URL-in-Identity-Provider-object-for-SmartConsole/m-p/246733#M41241</link>
      <description>&lt;P&gt;SOLVED&lt;/P&gt;&lt;P&gt;It is in the "&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;R81.20 Quantum Security Management Administration Guide&lt;/SPAN&gt;&lt;/SPAN&gt;", as explained by CP TAC, although a bit hidden: search for "SAML_IP_OR_&lt;SPAN class=""&gt;NAME&lt;/SPAN&gt;".&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Edit $CPDIR/tmp/.CPprofile.sh&lt;/LI&gt;&lt;LI&gt;Add this line to the file:&lt;P&gt;&lt;SPAN class=""&gt;SAML_IP_OR_NAME&lt;/SPAN&gt;=example.com; export &lt;SPAN class=""&gt;SAML_IP_OR_NAME&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;Restart the management server (cpstop;cpstart will do)&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;NOTE:&lt;/P&gt;&lt;P&gt;When creating an Identity Provider object for SmartConsole ("Managing Administrator Access"), the Return URL still shows the IP address. However, when SmartConsole performs the SAML request, it uses the FQDN in the Return URL silently. So, you MUST manually change the IP address for the FQDN when configuring the Return URL on the IdP (EntraID or similar).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2025 07:49:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Modify-Return-URL-in-Identity-Provider-object-for-SmartConsole/m-p/246733#M41241</guid>
      <dc:creator>FtW64</dc:creator>
      <dc:date>2025-04-17T07:49:19Z</dc:date>
    </item>
    <item>
      <title>Re: Modify 'Return URL' in Identity Provider object for SmartConsole SAML SSO</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Modify-Return-URL-in-Identity-Provider-object-for-SmartConsole/m-p/246739#M41242</link>
      <description>&lt;P&gt;Awesome, thanks for that! For the reference, page 84.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/CP_R81.20_Quantum_SecurityManagement_AdminGuide.pdf" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/CP_R81.20_Quantum_SecurityManagement_AdminGuide.pdf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2025 10:33:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Modify-Return-URL-in-Identity-Provider-object-for-SmartConsole/m-p/246739#M41242</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-17T10:33:04Z</dc:date>
    </item>
    <item>
      <title>Re: Modify 'Return URL' in Identity Provider object for SmartConsole SAML SSO</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Modify-Return-URL-in-Identity-Provider-object-for-SmartConsole/m-p/246740#M41243</link>
      <description>&lt;P&gt;Funny enough, that lab is standalone : - )&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2025 10:34:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Modify-Return-URL-in-Identity-Provider-object-for-SmartConsole/m-p/246740#M41243</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-17T10:34:18Z</dc:date>
    </item>
    <item>
      <title>Re: Modify 'Return URL' in Identity Provider object for SmartConsole SAML SSO</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Modify-Return-URL-in-Identity-Provider-object-for-SmartConsole/m-p/246747#M41249</link>
      <description>&lt;P&gt;Note that I'm using the SmartCenter Server as a SAML service provider. I'm not authenticating agains the gateway (or gateways) for Client VPN. Or are you referring to a management server cluster (management HA)?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2025 11:12:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Modify-Return-URL-in-Identity-Provider-object-for-SmartConsole/m-p/246747#M41249</guid>
      <dc:creator>FtW64</dc:creator>
      <dc:date>2025-04-17T11:12:05Z</dc:date>
    </item>
  </channel>
</rss>

