CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Authentication
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-01-22
phillyTD phillyTD is offline
Junior Member
 
Join Date: 2007-01-19
Posts: 3
Rep Power: 0
phillyTD has an average reputation (10+)
Default Client Auth and Radius Class Attribute

I have been searching these forums for any information on proper configuration of Radius and the Class attribute to lock users into certain rules. We had it working a while back where the class attribute matched the group name of the rule, so users logging would see "authenticated by Radius using nn rules" We use RSA's steel belted radius to do this. Since an upgrade to a patched version of RSA, I now see users connect and authenticate with all of our rules. It doesn't matter even if the class attribute has no matching ruleset on SmartDashboard.

I don't see anywhere in the logs where the class attribute is being seen. I also wonder why it is defaulting to all of the rules and not just denying all if they don't get a match. I know the class attribute is working, we have another VPN service that uses this and locks users into groups.

We need to lock users into the rules they need, and with thousands of existing users, cannot duplicate the user database on SmartDashboard, so want to depend on the generic* profile. I'm puzzled as why it worked, then stopped working.
Reply With Quote
  #2 (permalink)  
Old 2007-01-22
dharris dharris is offline
Junior Member
 
Join Date: 2006-08-03
Posts: 5
Rep Power: 0
dharris has an average reputation (10+)
Default Re: Client Auth and Radius Class Attribute

what platform are you running? Im assuming it's Connectra on Secure Platform?

Plenty of ways to debug RADIUS packets. try tcpdump on the cmd line if using splat or using ethereal.

you can see which attribute is passed back to connectra from eg tcpdump

05:01:48.188642 connectra-test.32828 > dummy.com.radius: rad-access-req 67 [id 57] Attr[ User{tester@dummy.com} [|radius] (DF)

rad-access-accept 99 [id 57] Attr[ Class{Connectra_users} Framed_ipaddr{10.10.10.10} [|radius]
Reply With Quote
  #3 (permalink)  
Old 2007-01-29
phillyTD phillyTD is offline
Junior Member
 
Join Date: 2007-01-19
Posts: 3
Rep Power: 0
phillyTD has an average reputation (10+)
Default Re: Client Auth and Radius Class Attribute

We're running a Unix platform. Unfortunately, I can't get the tcpdump to work. But while troubleshooting, I disabled all the rules, saved them, then tried logging in. I was authenticated by Radius, then it said I was allowed in via all seven (now 'disabled') rules.

What would cause the rule changes to basically be ignored. Could there be a problem between the smart Dashboard and the firewall? No changes seem to have worked. Short of deleting these rules and creating them, is there some way to get them to work the way they were originally?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 21:40.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0