- Products
- Learn
- Local User Groups
- Partners
- More
Access Control and Threat Prevention Best Practices
5 November @ 5pm CET / 11am ET
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Spark Management Portal and More!
Hi There,
I'm trying to run API towards the CheckPoint MDS CMAs.
From thread below thread I came to know that I need to generate the sid along with the domain name
When I try to run the query towards the MDS IP and without domain I can get the SID without any issues.
Once I send the domain as key, value parameter I'm getting authentication failures as below.
{
"code" : "err_login_failed",
"message" : "Authentication to server failed."
}
I can login to all the SmartConsole of CMA with the password, which I'm supplying to the REST API Post request.
Thanks in advance
Are you using latest JHF recommended for you version?
What does the audit log say?
What do you see if you try to authenticate with mgmt_cli locally on the MDS? For example, 'mgmt_cli -d "<CMA name>" login read-only true'.
I don't see any logs under the audit.
mgmt_cli command that you have shared was able to extract the SID successfully.
I have also noticed that when I give the domain UID instead of the name I am able to generate the SID.
Try <domain_name> instead of <CMA_name>
Hi @Amir_Senn
How can I differentiate the Domain Name and CMA name?
Best Regards,
Prashanth
Thank you Amir.
Indeed, I have tried both Domain and CMA names but in vain.
What platform are you using
Try: mgmt_cli login -d <domain_name> -r true
You can also try: mgmt_cli login -d <CMA_IP> -r true
If this succeeds than the problem is with credentials/permissions of that specific admin, if this doesn't login properly perhaps you have a different issue and would consult with support.
I'm using an Open Server to construct my python code.
I'm able to login with mgmt_cli login -d <domain_name> -r true and mgmt_cli login -d <CMA_IP> -r true. Both returns the SID and other variables while executing the command.
Further I'm using the admin account to execute my code which is a "Multi-Domain Super User" account. Do I need to add any permissions apart from that for the API call?
Indeed, I have allowed all the IP address for the API call.
Stange that the script is working for domain UID but not for the domain name.
From the API guide below, the API should take UID or name.
https://sc1.checkpoint.com/documents/latest/APIs/?#web/login~v1.9.1%20
Are you using latest JHF recommended for you version?
Thank you @Amir_Senn
The issue was due to the JHF. As I was running it on my lab I didn't install the hotfix.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 5 | |
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Wed 05 Nov 2025 @ 11:00 AM (EST)
TechTalk: Access Control and Threat Prevention Best PracticesThu 06 Nov 2025 @ 10:00 AM (CET)
CheckMates Live BeLux: Get to Know Veriti – What It Is, What It Does, and Why It MattersWed 05 Nov 2025 @ 11:00 AM (EST)
TechTalk: Access Control and Threat Prevention Best PracticesThu 06 Nov 2025 @ 10:00 AM (CET)
CheckMates Live BeLux: Get to Know Veriti – What It Is, What It Does, and Why It MattersTue 11 Nov 2025 @ 10:00 AM (CET)
Your First Response: Immediate Actions for Cyber Incident Containment- EMEAThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERTue 11 Nov 2025 @ 06:00 PM (COT)
San Pedro Sula: Risk Management al Horno: ERM, TEM & Pizza NightTue 11 Nov 2025 @ 06:00 PM (COT)
San Pedro Sula: Risk Management al Horno: ERM, TEM & Pizza NightAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY