CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Authentication
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-01-30
sergioaf sergioaf is offline
Junior Member
 
Join Date: 2006-07-31
Posts: 9
Rep Power: 0
sergioaf has an average reputation (10+)
Default User Auth working as Session Auth

Hello,

I just helped a customer to configure User Authentication for HTTP for a small group of users that reside on a DMZ. We created the users (with CP password authentication), the group of users and the rule on which that group (restricted to the DMZ network) is the source, the destination is any, the service is HTTP and the action has User Authentication, on which we selected the option "HTTP: All servers" in opposition of the default "predefined servers".

When the users try to browse a web page, they get the authentication challenge and they get authenticated ok, but then every time they click on a new link, the challenge window comes up again and they have to authenticate one more time in order to continue. Seems like even when it is User Authentication, its behaving like Session Authentication.

We checked the User Authentication Session Time out and it is on the default setting of 15 minutes both on Global Properties and the gateway object, which by the way is an active/standby HA pair.

Everything is NGX R61 and runs over SPLAT.

Has anyone seen this before? I don't seem to find an answer on the SK.

Thanks in advance for the help.

Regards
__________________
Sergio Alvarez
SEFISA Costa Rica
Reply With Quote
  #2 (permalink)  
Old 2007-01-30
sergioaf sergioaf is offline
Junior Member
 
Join Date: 2006-07-31
Posts: 9
Rep Power: 0
sergioaf has an average reputation (10+)
Default Re: User Auth working as Session Auth

Sorry, I just learned that in particular is the expected behavior when doing User Authentication with HTTP. I was under the impression that only Session Authentication would work like that.

We switched to Client Auth and got the expected results.
__________________
Sergio Alvarez
SEFISA Costa Rica
Reply With Quote
  #3 (permalink)  
Old 2007-01-31
BarryStiefel BarryStiefel is offline
Administrator
 
Join Date: 2005-08-11
Location: San Francisco, CA
Posts: 571
Rep Power: 10
BarryStiefel has disabled reputation
Default Re: User Auth working as Session Auth

Quote:
Originally Posted by sergioaf View Post
Hello,

I just helped a customer to configure User Authentication for HTTP for a small group of users that reside on a DMZ. We created the users (with CP password authentication), the group of users and the rule on which that group (restricted to the DMZ network) is the source, the destination is any, the service is HTTP and the action has User Authentication, on which we selected the option "HTTP: All servers" in opposition of the default "predefined servers".

When the users try to browse a web page, they get the authentication challenge and they get authenticated ok, but then every time they click on a new link, the challenge window comes up again and they have to authenticate one more time in order to continue. Seems like even when it is User Authentication, its behaving like Session Authentication.

We checked the User Authentication Session Time out and it is on the default setting of 15 minutes both on Global Properties and the gateway object, which by the way is an active/standby HA pair.

Everything is NGX R61 and runs over SPLAT.

Has anyone seen this before? I don't seem to find an answer on the SK.

Thanks in advance for the help.

Regards
User Authentication demands authentication for every single new TCP connection. Your browser will cache these credentials and silently provide them for you if you open another connection to the same server. If you close your browser, or time out, or go to a new web server, you must authenticate again.

This is why User Authentication is described as "Secure but intrusive". In real life, it's way too much of a pain to use for HTTP.
__________________
Barry J. Stiefel ("Stee-ful")
CCSA/CCSE/CCSE+/CCSI
President, CPUG
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 14:01.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0