- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello friends anyone faced similar issues ?
Gateway is on R80.40
Legacy authentication portal:
[http://firewall-vip.abc.com:900] is accessible on IE but no response on other browsers (Chrome, Edge)
Identity Awareness portal:
No issues with Identity Awareness portal, https://firewall-vip.abc.com
It is called "legacy" for a reason. I would strongly advise not to use any of the legacy auth features and rely on Identity Awareness instead.
_Val,
How are you?
How do I disable check point legacy authentication portal?
Ivan
Do you have any Client Authentication or User Authentication rules in your rulebase?
PhoneBoy,
Thanks for the feedback.
Yes, we have.
Configured SSL portal is configured with different URL and still legacy portal is being triggered. The legacy portal IP is configured by a class C private IP.
Ivan
Get rid of legacy authentications mentioned, the portal will go away.
_Val_
Yes, I want to remove, however, I didn't find sk that shows the way to remove. Can you tell me how to remove legacy portal settings?
Thanks.
You literally remove any rule with Client Authentication or User Authentication for starters.
If you want to prevent the portal from triggering entirely, comment out the relevant lines from $FWDIR/conf/fwauthd.conf
(i.e. put a # at the beginning of the line)
Indirect reference: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
PhoneBoy,
Thank you very mouch!
Ivan
Look in your policy for Client/Session authentication rules and remove them. The portal should disappear then.
Why is Client Authentication still in use?
This mechanism has been deprecated for many versions now.
Why is it still enabled by default even in R81.10 without ssl?
Given Client Auth is a legacy feature with a supported successor feature available (Identity Awareness with Captive Portal), there are no plans to enhance it.
If it's being activated with no Client Auth rules present, it's probably a bug and you should contact the TAC.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 25 | |
| 19 | |
| 14 | |
| 12 | |
| 12 | |
| 10 | |
| 6 | |
| 6 | |
| 5 | |
| 4 |
Wed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY