CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Authentication
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-08-14
BarryStiefel BarryStiefel is offline
Administrator
 
Join Date: 2005-08-11
Location: San Francisco, CA
Posts: 534
Rep Power: 10
BarryStiefel has disabled reputation
Default No Client Auth Rules Available

No Client Auth Rules Available



Client auth rules generally look like this:

Source Destination Service Action User-Group@Allowed-Sources Allowed-Destinations Allowed-Services Client Auth

A particular client auth rule applies when all of the following are true:
  • The username specified during the client authentication attempt is in the group User-Group
  • The source IP address of your connection to the firewall is in the group Allowed-Sources
  • The source IP address of your connection is specified in the username's allowed source (i.e. "Source" under the "Location" tab in the User Properties).

If you are getting the error message, it means that none of the client authentication rules meet all of the above criteria. If you can't figure out why, the latter is usually the culprit.

If nothing is listed in the user's allowed sources, then the user will generally not be able to authenticate from anywhere unless "Ignore User Database" is specified in the Client Authentication Properties. "Any" should be specified here, or at the very least, the desired allowed sources should.

-- PhoneBoy - 30 Dec 2003

FAQForm FAQs.Class: AuthenticationFAQs, TroubleshootingFAQs OperatingSystem?: FAQs.Version:
Reply With Quote
  #2 (permalink)  
Old 2005-08-18
rdunnell rdunnell is offline
Junior Member
 
Join Date: 2005-08-18
Posts: 1
Rep Power: 0
rdunnell has an average reputation (10+)
Default Re: No Client Auth Rules Available

No Client Auth rules can also be caused if you're using the legacy single sign on mechanism (sso-root user) and the system presenting the sso-root credentials is not in the allowed sources for that authentication rule.

For instance, if anyone at 10.1.1.x is allowed to log in, but the server handling single sign-on is at 10.1.2.x presents the credentials, the single sign on will not have any applicable rules even if the user is actually at 10.1.1.x. Add the server using the single sign on account into the group of allowed sources for that rule, and now the user will be properly logged in from 10.1.1.x.

(This is probably a bug or oversight, but might be driving some people nuts. It's probably pretty rare for the sso-root system to be used.)
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 06:13.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0