Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
smartinez02
Explorer

Check Point Quantum Gaia WebUI accessible from mobile device but not from Windows PC

Hello everyone, I'm experiencing an issue accessing the Gaia WebUI on a Check Point Quantum appliance. Environment: - Check Point Quantum appliance running Gaia Embedded - Management access is allowed from the local management VLAN - Windows PC and mobile phone are connected to the same network/VLAN Issue: When accessing the WebUI from a Windows PC, the browser returns SSL/TLS related errors such as: - ERR_SSL_PROTOCOL_ERROR - NET::ERR_CERT_COMMON_NAME_INVALID However, when accessing the same management IP and port from a mobile phone connected to the same VLAN, the login page loads successfully. What has been verified: - Both devices are on the same subnet/VLAN - Network connectivity exists - The management IP is reachable - The issue occurs on Windows browsers - Access from the mobile device works without issue Questions: 1. Has anyone seen Gaia Embedded WebUI work from mobile devices but fail from Windows browsers? 2. Are there any known TLS/cipher compatibility issues with specific Gaia Embedded releases? 3. Could browser security requirements be blocking older SSL/TLS configurations presented by the appliance? 4. Are there recommended checks from CLI to validate the WebUI SSL configuration? Any guidance would be appreciated. Thank you.
0 Kudos
2 Replies
PhoneBoy
Admin
Admin

Depending on the appliance/firmware version, yes, some appliances may use older ciphers and TLS versions that modern browsers may be configured not to allow. 
Knowing the precise appliance and firmware version will definitely help. 

You might also just be seeing messages related to self-signed certificates, which the web portal will use unless explicitly configured otherwise.
Seeing the exact error messages observed will definitely help.

0 Kudos
Bob_Zimmerman
MVP Gold
MVP Gold

It's not a cipher issue, it's the browser complaining about the metadata in the certificate. Specifically, it doesn't like something about the Common Name field, which is weird, because I'm not aware of any current browser which uses the contents of that field for anything. It has always been an unstructured text field, so everybody in the CA/B Forum switched to validating connections exclusively against the SANs like a decade ago. Plus it's self-signed, so none of the validation will ever pass anyway unless somebody manually adds the cert to the OS' or browsers' trust anchors.

I haven't used Gaia Embedded, but you can probably deal with this by generating a new certificate for the web UI with a CN you specify. You may need to try a few to get one Windows likes.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events