Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Zerat
Participant
Jump to solution

Yet another SAML issue with web version of smartconsole

Hi

I've tried to configure SAML SSO (with Azure AD) on my management server according to:
https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuid...

SmartConsole app is working fine - when I choose Identity provider, I'm redirected to the web and then correctly logged in.

With the web version, there is no identity provider selection.
When I use SSO login button from my apps portal, I get following error after browser redirection to [my.domain.name]/cpmws/saml/acs/sso 
the error is:

ERROR: error processing Saml response, it might be due to time out

 
Did I miss something in my config? The app version is working fine with it, only web gives me this error...

As for the domain, ENV variable SAML_IP_OR_NAME=[my.domain.name] seems to be added and looks fine (also: the app is working fine with it)

#######################################
If it's there, it must work. Hate to be beta-tester on GA
0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin

You don't see Identity Provider here?

image.png

Make sure you're on the latest Web Smartconsole using the command autoupdatercli show (look for mwc in the output) https://support.checkpoint.com/results/sk/sk170314 

product-name: mwc

   component-name: web_console
   component-branch: webconsole_AutoUpdate
   GA-Version: 0
   download-scheduler-active: true
   install-scheduler-active: true
   download-action: idle
   install-revert-action: idle

     installation-date: 2024-10-24_18:59:26
     package-branch-name: webconsole_AutoUpdate
     package-version: 120
     package-name: Check_Point_WEBCONSOLE_AUTOUPDATE_Bundle_T120_FULL.tgz
     package-installed: false
     package-installable: true
     package-previously-installed: true

     installation-date: 2024-10-24_19:36:50
     package-branch-name: webconsole_AutoUpdate
     package-version: 121
     package-name: Check_Point_WEBCONSOLE_AUTOUPDATE_Bundle_T121_FULL.tgz
     package-installed: true
     package-installable: true
     package-previously-installed: false

View solution in original post

15 Replies
PhoneBoy
Admin
Admin

You don't see Identity Provider here?

image.png

Make sure you're on the latest Web Smartconsole using the command autoupdatercli show (look for mwc in the output) https://support.checkpoint.com/results/sk/sk170314 

product-name: mwc

   component-name: web_console
   component-branch: webconsole_AutoUpdate
   GA-Version: 0
   download-scheduler-active: true
   install-scheduler-active: true
   download-action: idle
   install-revert-action: idle

     installation-date: 2024-10-24_18:59:26
     package-branch-name: webconsole_AutoUpdate
     package-version: 120
     package-name: Check_Point_WEBCONSOLE_AUTOUPDATE_Bundle_T120_FULL.tgz
     package-installed: false
     package-installable: true
     package-previously-installed: true

     installation-date: 2024-10-24_19:36:50
     package-branch-name: webconsole_AutoUpdate
     package-version: 121
     package-name: Check_Point_WEBCONSOLE_AUTOUPDATE_Bundle_T121_FULL.tgz
     package-installed: true
     package-installable: true
     package-previously-installed: false
Zerat
Participant

@PhoneBoy wrote:

You don't see Identity Provider here?

image.png

Make sure you're on the latest Web Smartconsole using the command autoupdatercli show (look for mwc in the output) https://support.checkpoint.com/results/sk/sk170314 

product-name: mwc

   component-name: web_console
   component-branch: webconsole_AutoUpdate
   GA-Version: 0
   download-scheduler-active: true
   install-scheduler-active: true
   download-action: idle
   install-revert-action: idle

     installation-date: 2024-10-24_18:59:26
     package-branch-name: webconsole_AutoUpdate
     package-version: 120
     package-name: Check_Point_WEBCONSOLE_AUTOUPDATE_Bundle_T120_FULL.tgz
     package-installed: false
     package-installable: true
     package-previously-installed: true

     installation-date: 2024-10-24_19:36:50
     package-branch-name: webconsole_AutoUpdate
     package-version: 121
     package-name: Check_Point_WEBCONSOLE_AUTOUPDATE_Bundle_T121_FULL.tgz
     package-installed: true
     package-installable: true
     package-previously-installed: false

I'm still on R81.20 and won't update soon, if that matters

#######################################
If it's there, it must work. Hate to be beta-tester on GA
0 Kudos
Ofir_Calif
Employee
Employee

Hi @Zerat,
Saml authentication is supported on R81.20 with Web SmartConsole.
Web SmartConsole has its own version that can be found with the command that @PhoneBoy wrote or with the following command:
cpinfo -y CPUpdates

Thanks,
Ofir.

Zerat
Participant

@PhoneBoy @Ofir_Calif thanks for help - it appeared, that we used the wrong link (BTW why Check Point still supports /smartview/
?)
for /smartconsole/ it works 🙂
on my defense - I always avoided web consoles if possible - only the infrastructure team sometimes uses the logs to search who to blame 😉

#######################################
If it's there, it must work. Hate to be beta-tester on GA
0 Kudos
PhoneBoy
Admin
Admin

SmartView does not support SAML authentication, correct.

0 Kudos
Ofir_Calif
Employee
Employee

Try Web SmartConsole,
While it does not have feature parity with the installed SmartConsole, it provides many of the day-to-day operations and better performance, and we are constantly improving it.

0 Kudos
Zerat
Participant

@Ofir_Calif @PhoneBoy 
How could I access SmartView now? It seems it neither supports Web version nor allow for SAML login to the app...
First CheckPoint ruined RADIUS functionality by refusing to patch protocol vulnerabilities, and now after switching to SAML, we are unable to use important functions (unless we use our breakglass account)
I need some network stats while diagnosing a performance issue (same goes with SmartUpdate and old config in Smart Dashboard - like QoS and HTTPS Inspection for incoming traffic..)

#######################################
If it's there, it must work. Hate to be beta-tester on GA
0 Kudos
PhoneBoy
Admin
Admin

Though it is clearly taking a bit longer to get Blast RADIUS fixes rolled out, we haven't "refused" to do so.
The Blast RADIUS SK was updated earlier this week with new information: https://support.checkpoint.com/results/sk/sk182516 
Still no word on exactly when it will be included in a JHF.

0 Kudos
Zerat
Participant

we had to remove the RADIUS hotfix to be able to upgrade to the new take 😞
Also it's a pity that migrating R77 consoles is taking CP soooo long - maybe some consolidation will do better than inventing new stuff for R82? 😉


#######################################
If it's there, it must work. Hate to be beta-tester on GA
0 Kudos
PhoneBoy
Admin
Admin

Adding stuff in SmartConsole is a bit more complicated than just reimplementing the UI in a different application.
HTTPS Inspection is now completely in SmartConsole (and has APIs) in R82...all while implementing new functionality.
There are a lot more APIs now in R82 as well.

 

0 Kudos
Ofir_Calif
Employee
Employee

Hi @Zerat,
if you need to access SmartView in your browser using SAML authentication you can use Web SmartConsole at
https://<MGMT-IP>/smartconsole.


Thanks,

Ofir

0 Kudos
Zerat
Participant

Hi @Ofir_Calif 

Could you guide me where could I find smartview monitor or smartupdate in the web /smartconsole/ ?
It's at least non-intuitive 😉

Regards
Zerat

#######################################
If it's there, it must work. Hate to be beta-tester on GA
0 Kudos
Ofir_Calif
Employee
Employee

Hi @Zerat,
Web SmartConsole support SmartView, the same way you use in https://<ip>/smartview
SmartUpdate and "SmartView monitoring" are not web application so they are not part of Web SmartConsole.

Thanks,
Ofir.

0 Kudos
Zerat
Participant

Yet, I need SmartView monitoring and smart update functionalities with modern authentication.
Especially the first one we use quite often for troubleshooting gateway issues.
Those consoles remember R77 (along with SmartDashboard - still required for some functionalities) - when will Check Point finally migrate the functionality to modern consoles/web apps?
It's ridiculous behavior for the vendor to leave so much of old mess...

#######################################
If it's there, it must work. Hate to be beta-tester on GA
0 Kudos
PhoneBoy
Admin
Admin

In general, the infrastructure leveraged by apps other than SmartConsole is older (fwm versus cpm) and wasn't designed with REST in mind.
In many cases, the functionality of these old apps has already been reimplemented, albeit in a different form.
In R82, we've added a lot more functionality in the API and eliminated one reason to need SmartConsole (HTTPS Inspection).

As far as I know, the only SmartUpdate functionality that hasn't been reimplemented in SmartConsole (as of R81.20) is offline contract updates (which I think can be handled via CLI).

SmartView Monitor...what specific things are you looking at there?
Most stats/monitoring can be found in cpview and/or Skyline.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events