Check Point Gateway Mobile Access Portal - SAML Relying Party Configuration for Cloud Authentication Service - RSA Ready Implementation Guide
This section describes how to integrate Check Point Gateway Mobile Access portal with RSA Cloud Authentication Service using SAML Relying Party.
Configure RSA Cloud Authentication Service
Perform these steps to configure RSA Cloud Authentication Service
Procedure
- Sign in to RSA Cloud Administration Console.
- Go to Authentication Clients menu and select Relying Parties.
- In the Relying Party Catalog, select Add a Relying Party.
- Click Add for Service Provider SAML.
- On the Basic Information page, enter the name for the application in the Name field and click Next Step.
- In the Authentication tab, select SecurID manages all authentication.
- Select a Primary Authentication Method and Access Policy as required and click Next Step.
- In the Connection profile section, go to the Service Provider section and enter the following details:
- ACS URL: Refer to Check Point configuration section to obtain this value.
- Service Provider Entity ID: Refer to Check Point configuration section to obtain this value.
- In the SAML Response Protection section, select IdP signs assertion within response.
- Click Download Certificate.
- Select Show Advanced Configuration, under the User Identity section configure Identifier Type and Property as the following example:
-
- Identifier Type > Auto Detect
- Property > Auto Detect
- Click Save and Finish.
- On the My Relying Parties page, click Edit and select Metadata option to download the metadata.
- Click Publish Changes to enable your application to SSO.
Configuration is complete.
Configure Check Point Mobile Access Portal
Perform these steps to configure Check Point Mobile Access Portal.
Procedure
- Log in to Check Point SmartConsole desktop application with admin credentials.
- From the left pane, go to Gateways & Servers tab.
- Double click the required deployed Check Point Gateway.
- In the General properties of the gateway, ensure that Mobile Access service is enabled.
Note: If Mobile Access service is not enabled, follow the prompt to enable the service. During the process, the Mobile Access portal URL is configured, and end users will use it to log in to the portal.
- In the Gateway & Servers tab, click New > More > User/Identity > Identity Provider.
- In the New Identity Provider window, choose a name for the RSA identity provider.
- Select the relevant Check Point Gateway from the Gateway dropdown list
- Select Mobile Access from the Service dropdown list.
- Copy the Entity ID and paste it in the Service Provider Entity ID field in RSA configuration.
- Copy the Reply URL and paste it in the ACS URL field in RSA configuration.
- Choose Import Metadata file.
- Go to the Metadata file downloaded from RSA, and the rest of the fields will be auto populated.
- In SmartConsole, click the Gateways & Servers panel.
- Open the Security Gateway object. From the left tree click Mobile Access > Authentication.
- In the Multiple Authentication Client Settings section, click Add to add a new Realm object.
- On the Login Option pane, in the Usage in Gateway section, clear the box Use in Capsule Workspace.
- On the Login Option pane, in the Authentication Method section, click Add.
- Select Identity Provider.
- Click the green [+] button and select the SAML Identity Provider object. Click OK.
- In SmartConsole, click Publish.
- Select the applicable policy and choose Access Control.
- Click Install to apply the policy.
The configuration is complete.
Return to Main page
Related Articles
How to hide or show authentication method tiles on the SecurID Access Prime Self-Service Portal's login home page (and oth… 50Number of Views Check Point Gateway Mobile Access Portal - RADIUS Configuration for Authentication Manager - RSA Ready Implementation Guide 44Number of Views Check Point Gateway Mobile Access Portal - RADIUS Configuration for Cloud Authentication Service - RSA Ready Implementatio… 26Number of Views Add a User to the Internal Database 41Number of Views Identity Source Properties 120Number of Views
Trending Articles
Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x
Don't see what you're looking for?