- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Introducing Check Point Quantum Spark 2500:
Smarter Security, Faster Connectivity, and Simpler MSP Management!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi,
I am getting errors trying to login to the "system data" domain on some R81.10 machines.
using the rest api: POST https://<ip>/web_api/login
it results with:
responseCode : 400, {"code":"err_login_failed","message":"Authentication to server failed."}
loging in to other domains of these machines works fine.
this happens on some R81.10 machine but not on others. (api version on the machine is 1.8)
Is it a known problem? Is there a solution.
Thanks
Can you share the syntax you used in the command?
Also, if you try this command locally using SSH, is there any different result?
Dont believe it is a known issue. As @Amir_Senn asked, maybe send us the exact syntax you are using. Its certainly odd it happens only on some machines.
Andy
Hellow,
the command is: https://<the ip-address>/web_api/login
the HTTP Method is: POST
and the body is:
{
"user": "the-user",
"password": "the-password",
"domain": "System Data",
"session-timeout": "60"
}
Is it same if you try https://ip_address/web_api_login ?
Andy
I do not understand. the documentation for login is:
{{server}}/login
for example https://192.168.0.120/web_api/login
this is what I do (of course with the relevant ip address)
I went to that link and it showed me web_api_login...not sure if it makes a difference, but it did work.
Are you sure the same credentials work, e.g. with SmartConsole?
Have you confirmed the configured user has API access as part of their permissions profile?
If so, then you may want to get the TAC involved: https://help.checkpoint.com
Also is the API set up to allow remote connections? By default, it doesn't. mgmt_cli local on the management will work, but HTTPS connections won't.
Step 1 should be to run `api status` on the SmartCenter (or MDS).
Step 2 is check access rights for named account.
Step 3 is test with mgmt_cli and same account.
....
The login to "system data" domain is only a part of what my program does.
All other requests work fine.
The program logs in (with no domain name) and gets information about gateways and servers list of domains and other. This all work fine with the same credentials.
It then tries to login to the "System Data". this fails on some machines.
Then depending it it is a multi domain system or not if logs in to the appropriate domain and gets information about "firewall policies and rules". This also works ok with the same credentials.
Can you send output of api status?
Try to connect without the domain name:
{
"user": "the-user",
"password": "the-password",
"session-timeout": "60"
}
This works and I am using this (no domain) for some API requests.
However for the /show-administrators request I must login to the "System Data" domain.
How about logging in with the same credentials locally on the system via 'mgmt_cli -d "System Data" login'?
If that doesn't work, does local root? 'mgmt_cli -d "System Data" -r true login'
If login via HTTP call fails but local works, that points towards the web service. If local login with the same credentials still fails, but local login with the local root works, that points to permissions.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
7 | |
7 | |
3 | |
2 | |
2 | |
2 | |
1 | |
1 |
Wed 03 Sep 2025 @ 11:00 AM (SGT)
Deep Dive APAC: Troubleshooting 101 for Quantum Security GatewaysThu 04 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: External Risk Management for DummiesWed 10 Sep 2025 @ 11:00 AM (CEST)
Effortless Web Application & API Security with AI-Powered WAF, an intro to CloudGuard WAFWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksWed 03 Sep 2025 @ 11:00 AM (SGT)
Deep Dive APAC: Troubleshooting 101 for Quantum Security GatewaysThu 04 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: External Risk Management for DummiesWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY