- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi
I am having problems when trying to load the SSL Network Extender portal of one of the firewalls that I administer, I have compared the general configuration of IPsec and Remote Access of another firewall that works correctly and is the same configuration. What would you recommend me to review specifically?
The authentication method is Legacy so I don't have certificates
Hey D,
I did remote session with Jose and helped him fix it. All it was is that in gaia portal, if you change port to non-standard, it changes option "according to policy", so then explicit rule is needed to allow access externally. If you just need it internally, then changing port to 4434 fpr example works for Gaia and also works on port 443 for snx. So Jose was fine with that and now he knows what to do in case they need to allow it on external interface. Thanks as always!
Andy
i have disabled the blade mobile access, everything had worked so far with ipsecVPN
What version/JHF level?
Are you referring the Mobile Access portal or the SNX portal (which is used to allow download of the SNX client when MAB is not used)?
Screenshot of what you see when you access the portal?
Hi PhoneBoy
HOTFIX_R80_10_JUMBO_HF Take: 279
I refer this portal SSL Network Extender, This is how it should work
Hi PhoneBoy
HOTFIX_R80_10_JUMBO_HF Take: 279
I refer this portal SSL Network Extender, This is how it should work
but when i try to the load of url by other gateway appear this form
Do you have an explicit rule in your access policy to allow this connection?
As a separate issue I recommend upgrading from R80.10 since it will be officially End of Support in the next few months.
No, i dont have an explicit rule to allow this connection. This connection do match with the implied rule, and now see an drop
How could I allow the connection? Could this have any repercussions? Modify the implied rule
When i do this SK, now i can to access, but to gaia portal not portal SSL Network Extender to connect to VPN. What else can I do?
Hey D,
I did remote session with Jose and helped him fix it. All it was is that in gaia portal, if you change port to non-standard, it changes option "according to policy", so then explicit rule is needed to allow access externally. If you just need it internally, then changing port to 4434 fpr example works for Gaia and also works on port 443 for snx. So Jose was fine with that and now he knows what to do in case they need to allow it on external interface. Thanks as always!
Andy
Nice work 🙂
As soo as I saw your response, first thing that popped into my head was possibility of MA and gaia portal using same port number. PLEASE ENSURE they are different and then push the policy and let us know.
Andy
Hang on...so what port is your Gaia portal now? Message me offline, lets do remote session, I want to see this. Something does not make sense.
Andy
my port gaia now is 4434 but the 443 still works, where would the remote session be?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
19 | |
12 | |
8 | |
7 | |
7 | |
6 | |
6 | |
4 | |
4 | |
3 |
Thu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAThu 18 Sep 2025 @ 02:00 PM (EDT)
Bridge the Unmanaged Device Gap with Enterprise Browser - AmericasMon 22 Sep 2025 @ 03:00 PM (CEST)
Defending Hyperconnected AI-Driven Networks with Hybrid Mesh Security EMEAMon 22 Sep 2025 @ 02:00 PM (EDT)
Defending Hyperconnected AI-Driven Networks with Hybrid Mesh Security AMERThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAThu 18 Sep 2025 @ 02:00 PM (EDT)
Bridge the Unmanaged Device Gap with Enterprise Browser - AmericasMon 22 Sep 2025 @ 03:00 PM (CEST)
Defending Hyperconnected AI-Driven Networks with Hybrid Mesh Security EMEAAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY