- Products
- Learn
- Local User Groups
- Partners
- More
Access Control and Threat Prevention Best Practices
5 November @ 5pm CET / 11am ET
Ask Check Point Threat Intelligence Anything!
October 28th, 9am ET / 3pm CET
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
Spark Management Portal and More!
Hi Guys,
I'm preparing for CCSA R80 and when I try to change the SSL-Port from Gaia through clish, the following output is given:
cp-mgmt> set web ssl-port 4434
WARNING This command is for initial use. SSL port should be set through SmartCon
sole. Changing the port may cause inconsistency with the settings on the SmartCo
nsole.
Are you sure you want to continue?(Y/N)[N]
n
I cannot find any option to set the ssl-port for a GAIA system from SmartConsole.
The SecurityManagement Guide for R80.20 got no hits, when searching for "ssl-port"
Does anyone know where to find that option?
Best Regard
Johannes
Johannes, the command set web ssl-port <port number> is correct and, remember, after execute this command you need to save this configuration with "save config". To verify you could run " grep 'httpd:ssl_port' /config/db/initial "
sk91380
"WARNING This command is for initial use. SSL port should be set through SmartDashboard. Changing the port may cause inconsistency with the settings on the SmartDashboard. Are you sure you want to continue?(Y/N)
[N]
"It is recommended to change the port using the Platform Portal section of the object in SmartDashboard.
Add the port to the end of the Main URL and push policy. "show web ssl-port" should now display the port in the Main URL
For Security Gateway:
In SmartConsole, perform:For Security Management Server:
Here we go: Platform portal under GW object.
Now, the main question is, why do you want to change SSL portal port from the default one?
yeah, that looks good.
But it seems, that you cannot change the default port for a mgmt server.
I guess you still need to change the admin-port from 443 to 4434 like in R77 when configuring CaptivePortal or sth. which also uses port 443.
But strange - when I add a new Gateway, the menu looks like the one in the picture, no Platform Portal branch
Yes and no.
In your example, you are on SMS. There is no Captive portal or any other GW side functionality, so no need to change SSL port. You still have Platform Portal option for GWs, as shown above.
On SMS/MDM the Gaia Port can be defined using the clish command „set web ssl-port“.
This is then default port for Gaia, Smartview, REST-API.
On gateways and clusters the platform portal is defining the Gaia Port but you can define different ports for UserCheck, MAB, IA CaptivePortal and maybe I forgot others.
In background everything is handled by multi-portal daemon which forwards requests on relevant port and path to relevant daemon/functionality listening on high-port.
Johannes, the command set web ssl-port <port number> is correct and, remember, after execute this command you need to save this configuration with "save config". To verify you could run " grep 'httpd:ssl_port' /config/db/initial "
sk91380
"WARNING This command is for initial use. SSL port should be set through SmartDashboard. Changing the port may cause inconsistency with the settings on the SmartDashboard. Are you sure you want to continue?(Y/N)
[N]
"It is recommended to change the port using the Platform Portal section of the object in SmartDashboard.
Add the port to the end of the Main URL and push policy. "show web ssl-port" should now display the port in the Main URL
For Security Gateway:
In SmartConsole, perform:For Security Management Server:
Isn't there a way to run GAIA on only the Management interface, and run other Portals on External/Internal interfaces?
Seems like that would be the simpler solution to this problem.
Anyone seen this issue?
Updated R81.10 ssl port from 443 to 4434 (on a new manager with migrated data) after this I get the following message when attempting to access the GAIA portal:
HTTP Status 404 - Not Found
Type Status Report
Description The origin server did not find a current representation for the target resource or is not willing to disclose that one exists.
Apache Tomcat/9.0.71
---
# grep 'httpd:ssl_port' /config/db/initial
httpd:ssl_port 4434
Port looks set correct looking at the above
TAC provided the solution, its known that when upgrading Endpoint Server from R80.40 or less to R81.x or above the httpd/httpd2 ports can get mixed up.
Resolution to this is documented in SK172485
#$UEPMDIR/system/install/gaia_apache_conf_regenerate 4434
#uepm_apache.sh port 443
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
31 | |
16 | |
6 | |
4 | |
3 | |
3 | |
3 | |
3 | |
3 | |
3 |
Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewWed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewWed 05 Nov 2025 @ 11:00 AM (EST)
TechTalk: Access Control and Threat Prevention Best PracticesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY