CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Authentication
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-02-21
Member
 
Join Date: 2006-06-19
Posts: 32
Rep Power: 0
wiz4rd has an average reputation (10+)
Default RSA Authentication on NG R55 MGMT

Hello guys,

I'm in trouble with configuration RSA on NG R55.

How do I authenticate myself on Management via RSA ?


I have done these steps:

1) Under administrator I have created one user and authentcation scheme "use Radius"

2) Under radius server i have create on server with the host (radius host) and version 2

3) Policy from MGMT to Radius server service udp 1812.


I remember that I have made the same on NGX and all works fine there.

Thank you Gurus :)
Reply With Quote
  #2 (permalink)  
Old 2007-02-21
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: RSA Authentication on NG R55 MGMT

Why use RADIUS and not SDI? (Assuming SPLAT here) create /var/ace and copy the sdconf.rec file to it you can set your management users to SecureID Authentication and all should be happy.

The one problem I've had with RSA is if you have more than one interface you really need to create the sdopts.rec file as such

# Place a new text file sdopts.rec next to the sdconf.rec file in the /var/ace directory.

# In the sdopts.rec file, insert the line CLIENT_IP=x.x.x.x, where "x.x.x.x" is the Cluster member's primary IP address, as defined on the ACE server.
Reply With Quote
  #3 (permalink)  
Old 2007-02-21
Member
 
Join Date: 2006-06-19
Posts: 32
Rep Power: 0
wiz4rd has an average reputation (10+)
Default Re: RSA Authentication on NG R55 MGMT

Hi,

Thx for answer.

I tryed your way but the connection instead on 1812 udp is on 5500 udp.

Any ideas ? :)
Reply With Quote
  #4 (permalink)  
Old 2007-02-21
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: RSA Authentication on NG R55 MGMT

5500 udp is the native SecureID port.

RSA/ACE supports two protocols

RADIUS and SDI. SDI has better support for the different token modes. RADIUS is for supporting devices that don't do SDI. RSA will tell you that the included RADIUS server isn't really useful as a general purpose RADIUS server and should not be used as such.
Reply With Quote
  #5 (permalink)  
Old 2007-02-21
Member
 
Join Date: 2006-06-19
Posts: 32
Rep Power: 0
wiz4rd has an average reputation (10+)
Default Re: RSA Authentication on NG R55 MGMT

My o.s. is win3k.,

I have put that file on c:\windows\system32 but in the log I see that the MGMT try to connect to ip address of my server rsa but the ip address is wrong.

I have used also the editor of rsa on sdconf.rec to change ip address but the error is the same :(.


Thank you for your support
Reply With Quote
  #6 (permalink)  
Old 2007-02-21
Member
 
Join Date: 2006-06-19
Posts: 32
Rep Power: 0
wiz4rd has an average reputation (10+)
Default Re: RSA Authentication on NG R55 MGMT

news,

Also when I deleted the sdconf.rec the ip address of rsa is the same wrong, i'm little confused without that file I shouldn't see any request on 5500.

Thx
Reply With Quote
  #7 (permalink)  
Old 2007-02-22
Member
 
Join Date: 2006-06-19
Posts: 32
Rep Power: 0
wiz4rd has an average reputation (10+)
Default Re: RSA Authentication on NG R55 MGMT

Oki now works fine,


I had to stop and restart fw1 service :).

Another question is possible to do the same on checkpoint 4.1 ? Because I can install database only on gateway and not on mgmt.

Many thanks again :)
Reply With Quote
  #8 (permalink)  
Old 2007-04-12
Junior Member
 
Join Date: 2007-02-09
Posts: 8
Rep Power: 0
Maliklahore has an average reputation (10+)
Default Re: RSA Authentication on NG R55 MGMT

Hi All
Under the same Issue :-( i am not allowed to post new?I dont know y?Anyway. I have an Issue related to the same subject.

1. I have RSA ACE Server
2. R55 MGMT.
3. Citrix CAG WI
4.RADIUS key placed in ACE
Rules for VPN are >>VPN User>any>any>any
Authantication type RADIUS + S.ID
Agent host defined Both Citrix + FW + ACE.
sdrec.conf was placed etc....
Everything was working fine.

I have upgraded RSA ACE Server and then >>>>>>its starts>>>
1. Users coming through Citrix WI CAG box are athunticated through RSA Secure ID token workes fine.

but

When same Users tried from Secure remote VPN my RSA gives me this error.

From: 03/27/2007 11:22:35 Activity Log Monitor Date:
03/27/2007 11:27:54
For: All Users Page: 1 of 1


Description (Site) Server


03/27/2007 10:24:36U musman/CITRIX 000076476130/Malik
03/27/2007 11:24:36L Passcode accepted rsaserver.abc.ie
03/27/2007 10:26:26U musman/FIREWALL 000076476130/Malik
03/27/2007 11:26:26L ACCESS DENIED, passcode incorrect rsaserver.abc.ie
03/27/2007 10:27:31U musman/FIREWALL 000076476130/Malik
03/27/2007 11:27:31L ACCESS DENIED, passcode incorrect rsaserver.abc.ie


Any Idea ?
Communication between RSA and Firewall is fine Rules are opend and was working fine there was no Issue. Same user Same Token is accepted as you can c in log. but same user with same token is ACCESS DENIED passcode incorrect when comes from Firewall >>>>

Thanks
MUsman

Last edited by Maliklahore; 2007-04-12 at 02:52.
Reply With Quote
  #9 (permalink)  
Old 2007-04-12
Junior Member
 
Join Date: 2007-02-09
Posts: 8
Rep Power: 0
Maliklahore has an average reputation (10+)
Default Re: RSA Authentication on NG R55 MGMT

I got the Solution .... have a look

1. The file to copy is "sdconf.rec", located in the ACE\data directory of the server. Copy to a directory on the firewall module (Not firewall management):

Windows: \winnt\system32

Unix/Linux: var/ace

2. On the RSA/ACE server, create a client for the firewall. Client type is:

Windows: NetOS

Unix/Linux: Unix Client

3. If the ACE/Server log says "Access denied/passcode incorrect" when authenticating through the firewall, you need to do more work as follows.



The problem is due to the firewall having more than one interface.



4. Install the ACE/Agent on the firewall. This will also install other diagnostic utilities.

5. Use the ACE/Agent utility, sdcfgval, to determine the IP address and name used by the ACE/Agent on the firewall.

From the ace/prog directory of the firewall, run

(Unix/Linux shown below):

# ./sdcfgval current_host

# ./sdcfgval current_host_addr

6. Use the name and address given by the two commands above to be the primary entry in the ACE/Server client database.

7. Add the other IP addresses of the firewall as secondary nodes.



Before trying to authenticate again, remove the node secret:

1. Delete the securid file from the firewall:

Windows: \winnt\system32

Unix/Linux: var/ace

2. On the ACE/Server, edit the firewall client, and clear the "node secret sent" box from the ACE/Server



Other things:

1. Make sure the firewall and the ACE/Server are time synchronized

2. Make sure your firewall rules allow SecurID communications going through

(the firewall implied rule is doing it already)

Last edited by Maliklahore; 2007-04-12 at 09:35.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 17:04.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0