Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
asdfuipo
Explorer

Mobile Access VPN Portal Always Loads GAIA

Hi All,

I am trying to setup a test lab with Mobile Access VPN, running R81.20. My Checkpoint VM has just two interfaces (192.168.10.10, 192.168.20.10). I would like to have the GAIA management portal accessible on one and Mobile Access VPN on the other.

I have followed a few different guides on setting up Mobile Access VPN, but I always get stuck.

No matter what I do every URL on both interfaces always loads the GAIA management portal. I have tried setting the "Main URL" under "Platform Portal" on the gateway but this makes no difference.

Is there a more detailed guide on how to configure Mobile Access VPN from scratch? Or am I just doing something else wrong here?

0 Kudos
8 Replies
PhoneBoy
Admin
Admin

Are you specifying /sslvpn as part of the URL?
This is noted in the product documentation: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_MobileAccess_AdminGuide/Cont...

By default, all portals (Gaia WebUI, SSL VPN, others) use the same IP and the correct portal is used based on URL.
Not sure you can change the requirement to use /sslvpn as part of the URL, even if multiportal is disabled.

asdfuipo
Explorer

Apologies, I should have specified. Yes I am requesting /sslvpn. Every URL loads the GAIA management portal, even ones that I would expect to 404 like /asdf.

0 Kudos
PhoneBoy
Admin
Admin

I'd start with troubleshooting Multiportal: https://support.checkpoint.com/results/sk/sk87920 
Based on what you find there, we can suggest other steps.

0 Kudos
asdfuipo
Explorer

sslvpn is not showing up when I run "mpclient list". Checking in SmartView it definitely seems like it is enabled, the box is checked and "Mobile Access" appears under "Access Blades". Is there something extra I need to do to get it configured and enabled with the MultiPortal Daemon?

0 Kudos
PhoneBoy
Admin
Admin

Try disabling the blade, pushing policy, then enabling the blade again, and pushing policy.

0 Kudos
asdfuipo
Explorer

Tried disabling, pushing, re-enabling. I've also tried again from scratch on a fresh VM. Still no luck unfortunately.

Is there a log file I can check to see any errors that might be occurring while applying the policy? In SmartConsole it looks like everything is enabled and working fine. But checking on the CLI it seems like nothing is enabled.

Alternatively is it possible to enable Mobile Access purely from the CLI?

0 Kudos
PhoneBoy
Admin
Admin

Did you perform all the debugging steps in sk87920?

0 Kudos
the_rock
Legend
Legend

Easy to fix...change web ui port.

clish -> set web ssl-port 4434

yes

save config

exit

Also change in smart console, push policy

Andy

 

Screenshot_1.png

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events