- Products
- Learn
- Local User Groups
- Partners
- More
Access Control and Threat Prevention Best Practices
5 November @ 5pm CET / 11am ET
Ask Check Point Threat Intelligence Anything!
October 28th, 9am ET / 3pm CET
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
Spark Management Portal and More!
Hi,
Noticed in R81.10 that there are a number of SuperUsers accounts
cachemanager@maas, healthcheck@maas, internal@maas, sessionmanager@maas, and web_mgmt_admin
The sessions tabs ALWAYS has live sessions for cachemanager@maas and we've not seen this prior to R81.10
Can anyone enlighten me on what these are?
Because they are MaaS we want to confirm their activity is not exfiltrating logs (or anything similar) from the environment.
I've raise a case with Check Point to ask them to advise but thought I'd ask here as well.
Thank you
#R81 #MaaS
Hi,
These admins (and sessions) are related to Harmony Endpoint Web UI service.
They are created when running web UI script which generated API keys for them so it’s not static keys and they are not stored anywhere (we pass them as environment variables to the Docker container).
They are created for background operation required by Web UI service when there is no active session (cache building and cache update).
Checking the option fixing it for the next jumbo hotfix.
I hope it clears the things.
Itamar.
Hi,
These admins (and sessions) are related to Harmony Endpoint Web UI service.
They are created when running web UI script which generated API keys for them so it’s not static keys and they are not stored anywhere (we pass them as environment variables to the Docker container).
They are created for background operation required by Web UI service when there is no active session (cache building and cache update).
Checking the option fixing it for the next jumbo hotfix.
I hope it clears the things.
Itamar.
They also show up in the Demo Mode servers as well, FYI.
Just to make it additionally clear this is not just on MAAS deployments of Endpoint servers.
Any r81 or above Endpoint deployment will contain the Endpoint web management portal and these accounts will be created and appear in the Management active administrator Sessions list from 127.0.0.1.
They are also used for SmartConsole Web (available from R81 and above), thus it will also apply to Network Security management as well.
Hi,
since those account kind of working locally in the background all the time, they make a mess in audit logs where i want to see and manage my actual users logs. Sure i can exclude them in the Rule above, but is there any plan from checkpoint to not show those users in administrators and audit logs since there is not much point?
What happens if I delete these accounts? Are they going to be created again automatically next time i use webUI?
thanks
Hi,
We are working on other alternatives that won't require us show those users in administrators and audit logs.
Currently, planned for next release.
We are also checking the option to fix it in Jumbo hotfix releases.
Itamar.
Hi Itamar,
Is there any update on this? Running R81.20 T26 and are still seeing a lot of sessions from internal@mass and sessionmanager@mass.
Thanks
By "next release" I assume it means R82.
We had a ticket opened for this issue and it was fixed in R82.
but R82 is not recomended version yet.
there won't be any other solution for R81.10 or R81.20?
thanks
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
21 | |
12 | |
7 | |
6 | |
4 | |
4 | |
4 | |
3 | |
3 | |
2 |
Tue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewTue 28 Oct 2025 @ 12:30 PM (EDT)
Check Point & AWS Virtual Immersion Day: Web App ProtectionTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewTue 28 Oct 2025 @ 12:30 PM (EDT)
Check Point & AWS Virtual Immersion Day: Web App ProtectionThu 30 Oct 2025 @ 03:00 PM (CET)
Cloud Security Under Siege: Critical Insights from the 2025 Security Landscape - EMEAThu 30 Oct 2025 @ 02:00 PM (EDT)
Cloud Security Under Siege: Critical Insights from the 2025 Security Landscape - AMERAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY