CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Authentication
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-08-13
BarryStiefel BarryStiefel is offline
Administrator
 
Join Date: 2005-08-11
Location: San Francisco, CA
Posts: 539
Rep Power: 10
BarryStiefel has disabled reputation
Default How to Integrate SecurID with FireWall-1?

How to Integrate SecurID with FireWall-1?



Note: This document assumes that the ACE/Server installation is functioning correctly; that the FW-1 is already enforcing a valid security policy, with whatever address translation is required for internal users to access the Internet; and that network connectivity between the ACE/Server and the FW-1 is unimpeded. You may need to explicitly define a rule on your FW-1 allowing SecurID traffic to and from the ACE/Server.
  1. On ACE/Server, define your firewall as a communications server within the "Add Client" menu of the administrative tool.
  2. On ACE/Server, be sure that the client hostname and IP address of the firewallagree with firewall's own definitions. This means that the nodename (as defined by the command "hostname") and the IP that name resolves to match that which is configured on the ACE/Server.
  3. On ACE/Server, list the other interfaces of the firewall under Secondary Nodes in the client configuration field. These must be listed in order for the ACE/Server to accept authentication requests from the firewall.
  4. On ACE/Server, go to "Assign Acting Servers" and specify primary and secondary ACE servers. Also generate sdconf.rec file from this screen and push to firewall. (Note that you might not need to Assign Acting Servers, though you likely will on IPSO)
  5. From FW-1 Management GUI, define a user group called SecurIDUsers. (From the "Manage" menu, select Users, New, Group.)
  6. From FW-1 Management GUI, define a new user (using the default template) named generic*. If NG FP3 and above, create a User Profile. Add this user to the group SecurIDUsers. Under properties for this user, define SecurID as the authentication method. [Note that only one generic* user can be configured on a FW-1 at any given time.]
  7. Add a FW-1 security rule with a source of SecurIDUsers@any, whatever destination and service you want to authenticate, and an action of UserAuth. Save, verify and install the security policy.
  8. Check the Network Address Translation rules on the FW-1 GUI to be sure that communications between the firewall and the ACE/Server are not address translated (address translation will really complicate the node secret exchange between the two boxes).
  9. On a Unix or IPSO platform, create the directory /var/ace.
  10. Copy /opt/ace/data/sdconf.rec from the ACE/Server (via FTP or disk) to /var/ace/sdconf.rec (on NT, this should be %SystemRoot%\system32\sdconf.rec).
  11. Bounce FireWall-1 (cprestart or fwstop; fwstart)
  12. Test authentication by initiating a connection to whatever destination and service you defined in your rule.

-- PhoneBoy - 30 Dec 2003

FAQForm FAQs.Class: AuthenticationFAQs FAQs.OS: FAQs.Version:
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 20:17.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0