CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Authentication
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-11-08
paypa paypa is offline
Junior Member
 
Join Date: 2005-08-22
Posts: 4
Rep Power: 0
paypa has an average reputation (10+)
Default Security and Access Configuration

Having problems with AAA configuration in NOKIA.

Using this document instructions: http://www.etsec.com/PDFs/nokia/Whit...ing_RADIUS.pdf

I already have Client Authentication setup on this firewall works perfectly. What else do I need to do to enable ACE to respond:

Receving these errors:
firewall[admin]# Nov 8 19:53:25 firewall [LOG_ERR] httpd: rad_send_request failed: No valid RADIUS responses received
Nov 8 19:53:25 firewall [LOG_ALERT] httpd: PAM_httpd: check pass; user unknown
Nov 8 19:53:25 firewall [LOG_NOTICE] httpd: PAM_httpd: authentication failure; root(uid=65534) -> <username> for httpd service
Reply With Quote
  #2 (permalink)  
Old 2006-11-08
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 787
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: Security and Access Configuration

You're mixing things up a bit by the looks of it.

Client Authentication and Nokia AAA are handled by separate processes, and the configuration for them is different.

Are you using Native SecurID for the Client Authentication?

If you want to get the Nokia box to use RADIUS auth, and you're using your ACE server for it, you'll need to enable RADIUS on the ACE server if you haven't already done so.

Are you seeing traffic generated from the firewall towards your RADIUS server? Are you seeing responses? What do your logs on the RADIUS server say?

Which IPSO version are you using?
Reply With Quote
  #3 (permalink)  
Old 2006-11-09
paypa paypa is offline
Junior Member
 
Join Date: 2005-08-22
Posts: 4
Rep Power: 0
paypa has an average reputation (10+)
Default Re: Security and Access Configuration

Are you using Native SecurID for the Client Authentication? Yes, I'm using Native SecurID with ACE Agent type being configured as a UNIX.

If you want to get the Nokia box to use RADIUS auth, and you're using your ACE server for it, you'll need to enable RADIUS on the ACE server if you haven't already done so.

I have both Radius and TACACS daemons running and have tried 1 or the other. From what I've been told, I can only setup the Agent Type in ACE to accept 1 or the other UNIX (Client Authentication) or Communication for TACACS or Radius.

Are you seeing traffic generated from the firewall towards your RADIUS server? Since I have suffient configured, I am seeing NEW-RADIUS traffic generated but then HTTP picks up since it is sufficient.

Are you seeing responses? What do your logs on the RADIUS server say? ACE is not seeing the request from the firewall.

Which IPSO version are you using?
Reply With Quote
Reply With Quote
  #4 (permalink)  
Old 2006-11-09
paypa paypa is offline
Junior Member
 
Join Date: 2005-08-22
Posts: 4
Rep Power: 0
paypa has an average reputation (10+)
Default Re: Security and Access Configuration

Quote:
Originally Posted by paypa View Post
Are you using Native SecurID for the Client Authentication? Yes, I'm using Native SecurID with ACE Agent type being configured as a UNIX.

If you want to get the Nokia box to use RADIUS auth, and you're using your ACE server for it, you'll need to enable RADIUS on the ACE server if you haven't already done so.

I have both Radius and TACACS daemons running and have tried 1 or the other. From what I've been told, I can only setup the Agent Type in ACE to accept 1 or the other UNIX (Client Authentication) or Communication for TACACS or Radius.

Are you seeing traffic generated from the firewall towards your RADIUS server? Since I have suffient configured, I am seeing NEW-RADIUS traffic generated but then HTTP picks up since it is sufficient.

Are you seeing responses? What do your logs on the RADIUS server say? ACE is not seeing the request from the firewall.

Which IPSO version are you using?
Reply With Quote
I'm using 3.7 IPSO
Reply With Quote
  #5 (permalink)  
Old 2006-11-09
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 787
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: Security and Access Configuration

So if the firewall is generating the RADIUS packets, but the ACE server is not logging it, does that indicate that RADIUS is possibly blocked along the way?

Run tcpdump or fw monitor on the firewall, and look for responses, as well as requests.
Reply With Quote
  #6 (permalink)  
Old 2006-11-09
paypa paypa is offline
Junior Member
 
Join Date: 2005-08-22
Posts: 4
Rep Power: 0
paypa has an average reputation (10+)
Default Re: Security and Access Configuration

Quote:
Originally Posted by northlandboy View Post
So if the firewall is generating the RADIUS packets, but the ACE server is not logging it, does that indicate that RADIUS is possibly blocked along the way?

Run tcpdump or fw monitor on the firewall, and look for responses, as well as requests.
I get error NO RESPONSE FROM RADIUS SERVER. But I am able to communicate between both systems...even opened ACLs to the VLANS. But in what mode should I have the agent configured so that it will allow both client and nokia authentication?
Reply With Quote
  #7 (permalink)  
Old 2006-11-09
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 787
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: Security and Access Configuration

Yes, you get an error saying no response from radius server, but if you actually look at the traffic on the wire, with tcpdump or fw monitor, do you see packets leaving your firewall and/or packets returning? Do you see packets reach your ACE server?

I'm not an ACE server expert, but can't you have it setup for both RADIUS and SecurID? Multiple agents if necessary
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 00:14.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0