CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Authentication
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-03-10
CheckMan CheckMan is offline
Junior Member
 
Join Date: 2005-12-07
Location: Trois-Rivières
Posts: 27
Rep Power: 0
CheckMan has an average reputation (10+)
Default Partially or Fully Authentication

If I need to use authentication when browsing with Internet Explorer (HTTP and HTTPS), which method that I need to use Partially or Fully Authentication??

Thanks
Reply With Quote
  #2 (permalink)  
Old 2006-03-10
Binary_01 Binary_01 is offline
Junior Member
 
Join Date: 2006-03-10
Posts: 15
Rep Power: 0
Binary_01 has an average reputation (10+)
Default Re: Partially or Fully Authentication

With partial Authentication the user will be prompted for user authentication for the the following services: HTTP, FTP, RLOGIN and telnet. Once the user is authenticated for these services, he will be authenticated for all other services permitted by the rule.

If the client first connects the an HTTPS server before the services listed above, the user will have to manualy authenticate.

Fully Authentication Sign-on works the same way except it will revert to session authentication for other services therefore requiring the installation of session clients on the desktops.

Keep in mind that client authentication and user authentication sends usernames and passwords unencrypted, you can change that by doing the following.

in the file: $FWDIR/conf/fwauthd.conf

delete this line:

259 fwssd in.aclientd wait 259

This will disabled Telnet client authentication.

Change the following line:

900 fwssd in.aclientd wait 900

to

900 fwssd in.aclientd wait 900 ssl:defaultCert

This way if you users need to authenticate via the Client authentication way (By connecting to your FW:900) it will now be done securely. I am not aware of any ways to secure user authentication at the moment.

Do backups before changing anything. :)

This is to the best of my knowledge and understanding.

To answer your question, I would use Partial authentication if I had too.

Cheers!

Phil.
Reply With Quote
  #3 (permalink)  
Old 2006-03-13
CheckMan CheckMan is offline
Junior Member
 
Join Date: 2005-12-07
Location: Trois-Rivières
Posts: 27
Rep Power: 0
CheckMan has an average reputation (10+)
Default Re: Partially or Fully Authentication

Or add the following entry in fwauthd.conf?

443 fwssd in.ahttpd wait 0

???

Thanks
Reply With Quote
  #4 (permalink)  
Old 2006-03-13
Binary_01 Binary_01 is offline
Junior Member
 
Join Date: 2006-03-10
Posts: 15
Rep Power: 0
Binary_01 has an average reputation (10+)
Default Re: Partially or Fully Authentication

Are you by an chance struggling with intergrating LDAP with your Checkpoint?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 04:43.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0