CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We've already had our first sign-ups!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 6/9, 7/14, 8/25, 10/6, 11/3, 12/8.
3. We have new forums in Portuguese and German (see below).
4. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
5. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Authentication
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-04-16
usman_a usman_a is offline
Junior Member
 
Join Date: 2006-02-04
Posts: 22
usman_a has an average reputation (10+)
Default Login expired on 31-dec-2003.

chaps

has anyone com across the following error?

Check Point FireWall-1 authenticated Telnet server running on firewall
User: test1
PASSCODE: **********
User test1 authenticated by SecurID
Login expired on 31-dec-2003.

The auth is set to user auth within the rule.

i have had a looka round the CP SK and came across something that suggested the error is related to time delay from a slow connection. I have checked all the details ie their user profile is set to2017, sec-id id is new and has few years left on it.

has anyone seen this error before?
__________________
I used to think a firewall was a borken router but now i know thats its a hub!
Reply With Quote
  #2 (permalink)  
Old 2007-04-17
melipla melipla is offline
Senior Member
 
Join Date: 2006-01-25
Posts: 667
melipla has an average reputation (10+)
Default Re: Login expired on 31-dec-2003.

Is the response that the SecurID server sends to the firewall normal?
Reply With Quote
  #3 (permalink)  
Old 2007-04-17
usman_a usman_a is offline
Junior Member
 
Join Date: 2006-02-04
Posts: 22
usman_a has an average reputation (10+)
Default Re: Login expired on 31-dec-2003.

Yes, the user connects to the fw via telnet on port 259 for auth. The user input their user name followed by pin+secid when prompted. This is where they are prompted with the Login expired on 31-dec-2003 message.
__________________
I used to think a firewall was a borken router but now i know thats its a hub!
Reply With Quote
  #4 (permalink)  
Old 2007-04-17
melipla melipla is offline
Senior Member
 
Join Date: 2006-01-25
Posts: 667
melipla has an average reputation (10+)
Default Re: Login expired on 31-dec-2003.

There's only two places where this could be expired. Either the SecurID user's token has expired. Or the Firewall user has expired. The message sounds suspiciously like a firewall user expired message--even the date format is the same as the user profile. What happens when you change the check point user's expiration to a different date, such as 01-01-2007, does the date in the error message change? I believe you have to push the policy after you change the expiration date....

Of course I'd also verify the proper time on each host, the firewall, the securid server and the client.
Reply With Quote
  #5 (permalink)  
Old 2007-04-17
usman_a usman_a is offline
Junior Member
 
Join Date: 2006-02-04
Posts: 22
usman_a has an average reputation (10+)
Default Re: Login expired on 31-dec-2003.

i thought that too.....i doubled checked the users profile and its date is set to 2016 by default and i changed it to 2017 and pushed the policy. I also check the secid on the ace server and the secid token has about 2 years left ..However the only thing i do not have control over is the client the user will connect to after the auth has happened.

Also the times are correct on the machines I have control over.

There is one thing to note.....the issue isn’t happening all the time it is intermit which leads to me to believe two things; the connection their trying to connect from is very much saturated and the point of initial connection to the point the user submits the password exceed the cp’s 2 minutes auth timers. if that’s not that case then its the target system they re trying to get to is at fault (i say as the initial rule was a user auth for ftp/telnet).
__________________
I used to think a firewall was a borken router but now i know thats its a hub!
Reply With Quote
  #6 (permalink)  
Old 2008-03-21
usman_a usman_a is offline
Junior Member
 
Join Date: 2006-02-04
Posts: 22
usman_a has an average reputation (10+)
Default Re: Login expired on 31-dec-2003.

All,

i know that i asked this question while when i came across this problem for te first time but it some hoe managed to fix itself. However i am seeing the same problem once again.

i am running a pair of crossbeam c25 with r55 and the last version of ace. The user auth by the webpage on port 900 and that’s where the get the error from. Can this be caused by their local machine ntp settings or firewalls not correctly talking back to the ace server? licences?
__________________
I used to think a firewall was a borken router but now i know thats its a hub!
Reply With Quote
  #7 (permalink)  
Old 2008-03-21
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 835
RayPesek has an average reputation (10+)
Default Re: Login expired on 31-dec-2003.

I believe that was the default FW-1 user expiration date.

Ray
Reply With Quote
  #8 (permalink)  
Old 2008-04-09
usman_a usman_a is offline
Junior Member
 
Join Date: 2006-02-04
Posts: 22
usman_a has an average reputation (10+)
Default Re: Login expired on 31-dec-2003.

the default on the firewall is set to 31-Dec-2016 and only about 6 users out of a 100 are affected......

any ideas anyone?
__________________
I used to think a firewall was a borken router but now i know thats its a hub!
Reply With Quote
  #9 (permalink)  
Old 2008-04-09
melipla melipla is offline
Senior Member
 
Join Date: 2006-01-25
Posts: 667
melipla has an average reputation (10+)
Default Re: Login expired on 31-dec-2003.

Quote:
Originally Posted by usman_a View Post
the default on the firewall is set to 31-Dec-2016 and only about 6 users out of a 100 are affected......

any ideas anyone?
Is it a coincidence that the problem is occurring almost a year later, around the time of the old day light savings date?
__________________
Its all in the documentation.
Reply With Quote
  #10 (permalink)  
Old 2008-04-13
usman_a usman_a is offline
Junior Member
 
Join Date: 2006-02-04
Posts: 22
usman_a has an average reputation (10+)
Default Re: Login expired on 31-dec-2003.

that's a interesting notion which i will check out however this is something that happens once in a while. The original post was before we upgraded the FW hardware and it stopped and now its happening on the new platform...
__________________
I used to think a firewall was a borken router but now i know thats its a hub!
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 11:40.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0