<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mobile Access - URL Rewrite Support for Web Apps that use SAML SSO in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-URL-Rewrite-Support-for-Web-Apps-that-use-SAML-SSO/m-p/274342#M14423</link>
    <description>&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 27 Mar 2026 16:47:00 GMT</pubDate>
    <dc:creator>Ingard</dc:creator>
    <dc:date>2026-03-27T16:47:00Z</dc:date>
    <item>
      <title>Mobile Access - URL Rewrite Support for Web Apps that use SAML SSO</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-URL-Rewrite-Support-for-Web-Apps-that-use-SAML-SSO/m-p/130828#M7968</link>
      <description>&lt;P&gt;I'm trying to put web apps in Mobile Access that leverage SAML based SSO (we use Okta, but it's the same for any SAML SSO provider).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The challenge is, that the application redirects to the SAML IdP just fine, but when the IdP redirects back to the relying party (SP), it is using the configured Relying Party URL.&amp;nbsp; So we need to send the IdP traffic through Mobile Access in order for MAB to be able to rewrite those URLs as they contain the SAML assertion that needs to go to the SP.&lt;/P&gt;&lt;P&gt;I have tried adding the SAML IdP URL as a web application and including it in the rules.&amp;nbsp; This almost works, but it seems that the URL rewriting code is either not able to or just isn't updating the SRI in the URL causing the browser to not load it as the SRI value doesn't match the rewritten URL.&lt;/P&gt;&lt;P&gt;I had a TAC case opened with my Diamond Engineer (&lt;SPAN&gt;6-0002161253)&lt;/SPAN&gt;, but it got closed in the transition from one engineer to another because the debugs that I had provided to the case got lost and I didn't want to go through an gather debugs all over for something that I clearly documented as an issue with the MAB URL rewrite.&lt;/P&gt;&lt;P&gt;I wanted to ask the community if anyone had been able to successfully add a web application to MAB that used SAML authentication and, if so, now.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;heath&lt;/P&gt;</description>
      <pubDate>Fri, 01 Oct 2021 14:31:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-URL-Rewrite-Support-for-Web-Apps-that-use-SAML-SSO/m-p/130828#M7968</guid>
      <dc:creator>Heath_H</dc:creator>
      <dc:date>2021-10-01T14:31:05Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - URL Rewrite Support for Web Apps that use SAML SSO</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-URL-Rewrite-Support-for-Web-Apps-that-use-SAML-SSO/m-p/130978#M7969</link>
      <description>&lt;P&gt;This may not be supported.&lt;BR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/5699"&gt;@MaksimBahunou&lt;/a&gt;&amp;nbsp;can you confirm?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 00:26:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-URL-Rewrite-Support-for-Web-Apps-that-use-SAML-SSO/m-p/130978#M7969</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-10-05T00:26:52Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - URL Rewrite Support for Web Apps that use SAML SSO</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-URL-Rewrite-Support-for-Web-Apps-that-use-SAML-SSO/m-p/130988#M7970</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;, you are right. Such configuration is not supported.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 06:42:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-URL-Rewrite-Support-for-Web-Apps-that-use-SAML-SSO/m-p/130988#M7970</guid>
      <dc:creator>MaksimBahunou</dc:creator>
      <dc:date>2021-10-05T06:42:33Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - URL Rewrite Support for Web Apps that use SAML SSO</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-URL-Rewrite-Support-for-Web-Apps-that-use-SAML-SSO/m-p/131021#M7971</link>
      <description>&lt;P&gt;So what is the answer for that situation as more and more applications are leveraging SSO, including internal ones.&amp;nbsp; Further, SRI is a security measure and I only see it's use increasing in web-based applications.&lt;/P&gt;&lt;P&gt;Is the recommendation to move to something like an F5 in a DMZ that better handle URL rewriting for internal web applications coupled with SSO and MFA and just avoid the need for an SSL VPN entirely?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 11:59:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-URL-Rewrite-Support-for-Web-Apps-that-use-SAML-SSO/m-p/131021#M7971</guid>
      <dc:creator>Heath_H</dc:creator>
      <dc:date>2021-10-05T11:59:10Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - URL Rewrite Support for Web Apps that use SAML SSO</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-URL-Rewrite-Support-for-Web-Apps-that-use-SAML-SSO/m-p/131163#M7972</link>
      <description>&lt;P&gt;We have a different solution that handles this use case better called Harmony Connect.&lt;BR /&gt;The deployment/management model is a bit different, but it achieves the same result.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Oct 2021 16:11:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-URL-Rewrite-Support-for-Web-Apps-that-use-SAML-SSO/m-p/131163#M7972</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-10-06T16:11:36Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - URL Rewrite Support for Web Apps that use SAML SSO</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-URL-Rewrite-Support-for-Web-Apps-that-use-SAML-SSO/m-p/222301#M7973</link>
      <description>&lt;P&gt;Is this still the case today?&amp;nbsp; &amp;nbsp;Harmony&amp;nbsp; Connect is recommended over sslvpn with SAML and web apps?&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's odd that saml sso is supported for snx, Endpoint Security fat clients but not web apps.&amp;nbsp; &amp;nbsp;It's not supported with mobile access portal or the identity awareness browser portal?&amp;nbsp; &amp;nbsp;I'll check out the harmony connect, it looks like its a solution with the infinity portal.&amp;nbsp; &amp;nbsp;Can it it be used to access on premise resources?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 18:11:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-URL-Rewrite-Support-for-Web-Apps-that-use-SAML-SSO/m-p/222301#M7973</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2024-07-30T18:11:50Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - URL Rewrite Support for Web Apps that use SAML SSO</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-URL-Rewrite-Support-for-Web-Apps-that-use-SAML-SSO/m-p/222303#M7974</link>
      <description>&lt;P&gt;Since that post was made, Harmony SASE is now the solution.&lt;BR /&gt;The Mobile Access Portal itself supports SAML authentication (has since R80.40).&lt;/P&gt;
&lt;P&gt;Are you talking about a backend app (accessible via the MAB frontend) that requires SAML authentication?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 18:30:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-URL-Rewrite-Support-for-Web-Apps-that-use-SAML-SSO/m-p/222303#M7974</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-30T18:30:43Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - URL Rewrite Support for Web Apps that use SAML SSO</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-URL-Rewrite-Support-for-Web-Apps-that-use-SAML-SSO/m-p/222304#M7975</link>
      <description>&lt;P&gt;TAC just closed my case referencing this post, that SAML authentication wasn't supported for MAB web applications.&amp;nbsp; &amp;nbsp;No, I don't need SAML for the backend apps, I'm just trying to get to them!&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 18:33:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-URL-Rewrite-Support-for-Web-Apps-that-use-SAML-SSO/m-p/222304#M7975</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2024-07-30T18:33:49Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - URL Rewrite Support for Web Apps that use SAML SSO</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-URL-Rewrite-Support-for-Web-Apps-that-use-SAML-SSO/m-p/222306#M7976</link>
      <description>&lt;P&gt;The root post for this relates to backend apps that require SAML authentication to access.&lt;BR /&gt;Meanwhile, the frontend of MAB&amp;nbsp;very much supports SAML authentication.&lt;BR /&gt;It's even in the documentation:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_MobileAccess_AdminGuide/Content/Topics-MABG/SAML-Identity-Provider-Mobile-Access.htm?Highlight=saml" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_MobileAccess_AdminGuide/Content/Topics-MABG/SAML-Identity-Provider-Mobile-Access.htm?Highlight=saml&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 19:09:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-URL-Rewrite-Support-for-Web-Apps-that-use-SAML-SSO/m-p/222306#M7976</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-30T19:09:49Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - URL Rewrite Support for Web Apps that use SAML SSO</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-URL-Rewrite-Support-for-Web-Apps-that-use-SAML-SSO/m-p/274305#M14421</link>
      <description>&lt;P&gt;Does the same problem still exists ?&lt;/P&gt;
&lt;P&gt;We want to access an web-application via MobileAccessPortal which does the authentication via SAML. Authentication to the MOB portal itself via SAML is working fine but access to the published application not.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Mar 2026 06:35:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-URL-Rewrite-Support-for-Web-Apps-that-use-SAML-SSO/m-p/274305#M14421</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2026-03-27T06:35:05Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - URL Rewrite Support for Web Apps that use SAML SSO</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-URL-Rewrite-Support-for-Web-Apps-that-use-SAML-SSO/m-p/274342#M14423</link>
      <description>&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Mar 2026 16:47:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-URL-Rewrite-Support-for-Web-Apps-that-use-SAML-SSO/m-p/274342#M14423</guid>
      <dc:creator>Ingard</dc:creator>
      <dc:date>2026-03-27T16:47:00Z</dc:date>
    </item>
  </channel>
</rss>

