- Products
- Learn
- Local User Groups
- Partners
- More
Ink Dragon: A Major Nation-State Campaign
Watch HereAI Security Masters E5:
Powering Prevention: The AI Driving Check Point’s ThreatCloud
The Great Exposure Reset
AI Security Masters E4:
Introducing Cyata, Securing the Agentic AI Era
CheckMates Go:
CheckMates Fest
Hello friends anyone faced similar issues ?
Gateway is on R80.40
Legacy authentication portal:
[http://firewall-vip.abc.com:900] is accessible on IE but no response on other browsers (Chrome, Edge)
Identity Awareness portal:
No issues with Identity Awareness portal, https://firewall-vip.abc.com
It is called "legacy" for a reason. I would strongly advise not to use any of the legacy auth features and rely on Identity Awareness instead.
_Val,
How are you?
How do I disable check point legacy authentication portal?
Ivan
Do you have any Client Authentication or User Authentication rules in your rulebase?
PhoneBoy,
Thanks for the feedback.
Yes, we have.
Configured SSL portal is configured with different URL and still legacy portal is being triggered. The legacy portal IP is configured by a class C private IP.
Ivan
Get rid of legacy authentications mentioned, the portal will go away.
_Val_
Yes, I want to remove, however, I didn't find sk that shows the way to remove. Can you tell me how to remove legacy portal settings?
Thanks.
You literally remove any rule with Client Authentication or User Authentication for starters.
If you want to prevent the portal from triggering entirely, comment out the relevant lines from $FWDIR/conf/fwauthd.conf
(i.e. put a # at the beginning of the line)
Indirect reference: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
PhoneBoy,
Thank you very mouch!
Ivan
Look in your policy for Client/Session authentication rules and remove them. The portal should disappear then.
Why is Client Authentication still in use?
This mechanism has been deprecated for many versions now.
Why is it still enabled by default even in R81.10 without ssl?
Given Client Auth is a legacy feature with a supported successor feature available (Identity Awareness with Captive Portal), there are no plans to enhance it.
If it's being activated with no Client Auth rules present, it's probably a bug and you should contact the TAC.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 33 | |
| 20 | |
| 18 | |
| 10 | |
| 10 | |
| 9 | |
| 9 | |
| 8 | |
| 7 | |
| 6 |
Tue 17 Mar 2026 @ 03:00 PM (CET)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - EMEATue 17 Mar 2026 @ 02:00 PM (EDT)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - AMERWed 18 Mar 2026 @ 10:00 AM (CET)
The Cloud Architects Series: An introduction to Check Point Hybrid Mesh in 2026 - In Seven LanguagesThu 19 Mar 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #2: AI Security Challenges and SolutionsTue 17 Mar 2026 @ 03:00 PM (CET)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - EMEATue 17 Mar 2026 @ 02:00 PM (EDT)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - AMERWed 18 Mar 2026 @ 10:00 AM (CET)
The Cloud Architects Series: An introduction to Check Point Hybrid Mesh in 2026 - In Seven LanguagesThu 19 Mar 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #2: AI Security Challenges and SolutionsTue 24 Mar 2026 @ 04:00 PM (CET)
Maestro Masters EMEA: Hyperscale Firewall Architectures and OptimizationTue 24 Mar 2026 @ 06:00 PM (COT)
San Pedro Sula: Spark Firewall y AI-Powered Security ManagementThu 26 Mar 2026 @ 06:00 PM (COT)
Tegucigalpa: Spark Firewall y AI-Powered Security ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY