CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Authentication
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-09-26
Junior Member
 
Join Date: 2006-09-26
Posts: 2
Rep Power: 0
Chrys has an average reputation (10+)
Default No Authentification required

Greetings everybody,

I have a small problem trying to impliment user authentification on Telnet.

I'm using a Radius server to authenticate my users, with a generic external group. This works fine to authenticate users trying to use the dashboard or the secure client.

I created a rule
SRC DST VPN tr SERVICE ACTION
telnet_grp@any telnet_svr Any Telnet User Auth

When I telnet I get the following which makes me think that it's being intercepted by the FW.

Check Point FireWall-1 authenticated Telnet server running on lu3cdudfw
Connected to xxx.xxx.xxx.xxx

But it sent us directly in the server w/o asking for any CheckPoint authentification.

In the tracker I can see that the traffic is accepted.
But in the information line, it says No authentification required.

I've already installed the User DB on the firewall and created CheckPoint users to see if maybe it wasn't possible to use Radius, but it's all the same.

Any Idea ?

Regards
Chrys
Reply With Quote
  #2 (permalink)  
Old 2006-09-27
Junior Member
 
Join Date: 2006-09-27
Posts: 12
Rep Power: 0
theoracle has an average reputation (10+)
Default Re: No Authentification required

You need to change your rule action from "user auth" to "session auth".
I believe you want to be authenticated for each connected session.
Reply With Quote
  #3 (permalink)  
Old 2006-09-29
Junior Member
 
Join Date: 2006-09-26
Posts: 2
Rep Power: 0
Chrys has an average reputation (10+)
Default Re: No Authentification required

Hi,
I tried that, but I get a timeout.
In the tracker, I can see errors.

reason: Connection to Session Agent failed


Chrys
Reply With Quote
  #4 (permalink)  
Old 2006-10-02
Junior Member
 
Join Date: 2006-09-27
Posts: 12
Rep Power: 0
theoracle has an average reputation (10+)
Default Re: No Authentification required

The placement of the rule in the policy is important. Apparently, the rule works to some degree, as you are receiving the error: connection to session agent failed. Try moving your Telnet rule to the top of the policy as a test. This would confirm that other rules are not affecting this connection problem. I recall this authentication issue present on previous versions of FW-1 as well. I'll post again when I remember the actual fix.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 17:05.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0