CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Authentication
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-08-10
thanhdt thanhdt is offline
Junior Member
 
Join Date: 2006-08-10
Posts: 5
Rep Power: 0
thanhdt has an average reputation (10+)
Default Problems with Radius Authentication !

Here are requirements:

- Users must be authenticated before access to any resources(server1, server2)

- Authorize:

+ user1 is allowed to access to server1, denied to server2

+ user2 is allowed to access to server2, denied to server1

What i did

on Check Point

1. Create Radius Server
2. Create the External User Profile (generic* user), Authentication Scheme: Radius
3. Create the number of User Groups (rad_user1, rad_user2...), only specify the name.
4. edit objects5_0.C: set the attribute add_radius_groups(false) -> add_radius_groups(true). CpStop / CpStart ( Firewall is in SecurePlatform)
5. create 2 rules authentication :

Rule 1:
SOURCE: rad_user1@any
DESTINATION: server1
SERVICE: any
ACTION: Client Auth

Rule 2:
SOURCE: rad_user2@any
DESTINATIOn: server2
SERVICE: any
ACTION: Client Auth

on Radius Server (Funk Radius)

Create 2 users:

username: user1
password: user1
class attribute: rad_user1

username: user2
password: user2
class attribute: rad_user2


but when users connect to http://firewallip:900 to authenticate, and input their usernames, passwords, CP displayed messages:
"Client Authentication Remote Service
FireWall-1 message: User tu1 authenticated by Radius authentication
No Client Authentication Rules Are Available
End session"

these words may be mean Check Point didn't understand two rules.

anyone helps me ? thanks
Reply With Quote
  #2 (permalink)  
Old 2006-08-10
dbedit dbedit is offline
Senior Member
 
Join Date: 2006-06-14
Location: The Netherlands
Posts: 153
Rep Power: 3
dbedit has an average reputation (10+)
Default Re: Problems with Radius Authentication !

What sign on method do you use for client authentication?? Double click 'client auth'.??
Reply With Quote
  #3 (permalink)  
Old 2006-08-10
dbedit dbedit is offline
Senior Member
 
Join Date: 2006-06-14
Location: The Netherlands
Posts: 153
Rep Power: 3
dbedit has an average reputation (10+)
Default Re: Problems with Radius Authentication !

Forget my question.....

looks very much like sk24858 you implemented.
Reply With Quote
  #4 (permalink)  
Old 2006-08-10
thanhdt thanhdt is offline
Junior Member
 
Join Date: 2006-08-10
Posts: 5
Rep Power: 0
thanhdt has an average reputation (10+)
Default Re: Problems with Radius Authentication !

Quote:
Originally Posted by dbedit
Forget my question.....

looks very much like sk24858 you implemented.
yes, i search secure knowledge and find this sk24858 solution for authentication with radius, but i was not successful. :(

do u have any experience to share with me ?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 03:15.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0