- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Recently installed a pair of Spark appliances running R82.00.10. I attempted to access the CLI using the option in the WEBUI which was via Firefox (See below, the issue is not seen using Edge):
When clicking on CLI button, the below was presented with an untrusted certificate, now in the new dialog box there was no option to actually accept the untrusted certificate (this was out of the box certificate b.t.w).
The client itself initiates a connection on port TCP/5555 (believe this is a SSL based connection) back to the appliance
This issue appears to be more a firefox problem rather then a Checkpoint one (but I would debate the potentially port 5555 should not be used, and full GAIA appliances don't experience the same issue).
How was this resolved:
With the above screenshot open, add a certificate ie. <IP>:5555
Once this is done, your CLI connection should work.
I would like to request Checkpoint investigate this further with the firefox browser, and potentially change this so it works using port 22 perhaps?
TAC are aware of this.
Is it same issue regardless of what browser you use?
No - I tested with Firefox and Edge, and the issue only appeared in Firefox.
I have another issue related to device certs, which may be the same type of resolution, TAC are investigating that through a separate case, but have verified I've done everything correctly.
Try set below to false, restart browser, try again.
But why would that make a difference when the issue is firefox actually requiring an open connection into the GW so it can retrieve the cert?
I can certainly give it a try, but would I want to leave it like that, I'm not sure.
Just to see if quic protocol could be causing it.
For the WEB CLI, port 5555 could be changed to a different port from advanced settings on a supported version.
Just for testing, maybe changing the port will resolve the error on Firefox?
See here:
Connections to Port 5555 Fail on Quantum Spark Devices
https://support.checkpoint.com/results/sk/sk183637
I'm not sure if changing the port to 22 will work with the current design though.
Good call, Tom. Appears even with higher version, those commands mignt be needed.
We did try this, changed the port to 6666 as an example but still this did not work. I did ash about changing the port to 22, but we did not try this, way...It looks like the connection is SSL based not SSH based.
Considering the entire purpose of this feature is to not have to use a native SSH client, the communication must occur over HTTPS.
Due to the embedded nature of the OS on Spark devices (not to be confused with SPARC devices), the web server implementation is different than regular appliances.
As such, that communication needs to occur over a different port, which can be changed.
I find it odd that Firefox doesn't give an option to "Accept and Continue" (as it did when I connected to the appliance) and I have to go through the process of fully trusting the self-signed certificate.
Totally agree, TAC even replicated it, but said it was a firefox issue, which on the face of it, it does look like it, however I think Checkpoint should be looking to resolve this, because firefox is widely used.
For me - by posting the issue and resolution I came to here, will help others facing this strange issue.
Totally valid point, Firefox should work.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY