CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Authentication
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-08-31
karimi karimi is offline
Member
 
Join Date: 2005-08-22
Posts: 54
Rep Power: 4
karimi has an average reputation (10+)
Default RADIUS for smart dashboard problem

Hi,

I want my admins to logon to SmartDashboard using our Radius server. I have configured a test user (AdminAuth=RADIUS) and selected the RADIUS server object .

The RADIUS server object has Host=Win2K box running Microsoft Internet Authenticatiion Server (RADIUS); Service=RADIUS(udp); Shared Secret (abc123); Version=RADIUS v.1.0 Protocol=PAP.

When I try to logon from my desk to the management center via SmartDashboard using this test user name, nothing happens and I get - "Authentication to Server X.X.X.X Failed"

When I try using my normal FW-1 Adminsitrator account, its fine. My rules allow the Mgmt Center wide open access to the Radius server, so it's not a connectivity or rule issue.

ANy clues?

-k
Reply With Quote
  #2 (permalink)  
Old 2006-08-31
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 787
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: RADIUS for smart dashboard problem

Any logs on the RADIUS server giving any indication of what's happening? e.g. if it's even trying to auth, or if something else is going on.
Reply With Quote
  #3 (permalink)  
Old 2006-08-31
karimi karimi is offline
Member
 
Join Date: 2005-08-22
Posts: 54
Rep Power: 4
karimi has an average reputation (10+)
Default Re: RADIUS for smart dashboard problem

Hi Northlandboy,

The log files directory on the Win2K server are empty..even though the Internet Authentication Server is set to log Rejected+Successful authentication requests...

Question- Is my Radius client the Managment center IP or the Firewall IP..? I suspect the Mgmt Center IP becuse that is where I will be authenticating SmartDashboard Admin users from..(but i have the FW ips in there also)

The IAS is running normally.. with the FW EMC IP defined.
Ports: 1812,1645/1813,1646
Radius Standard
Shared Secret=defined
Message Authenticator=OFF

Active Directory is running normally, coz I can login into Win2K using the test user I created in AD. It is a member of the domain and Under Dial-In Tab, it is allowed Access.
Reply With Quote
  #4 (permalink)  
Old 2006-08-31
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 787
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: RADIUS for smart dashboard problem

In this case, it would be the SmartCenter server IP.
Reply With Quote
  #5 (permalink)  
Old 2006-08-31
karimi karimi is offline
Member
 
Join Date: 2005-08-22
Posts: 54
Rep Power: 4
karimi has an average reputation (10+)
Default Re: RADIUS for smart dashboard problem

Northlandboy,

It is fixed now.

The problem, at least as far as I can tell, is that Version in the RADIUS object was set to version 1.0; which did not work.

When I changed it to Version 2.0, now it works, and the user authenticates no problem.

I am not sure why changing the version in the RADIUS object fixed this.

I also see logs now in the \WIN\SYSTEM32\LOGS\ directory preceeding with INxxxxxxxxx.log and it shows the RADIUS authentications.

Thanks for your assistance Northlandboy!

cheers

~mike
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 00:28.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0