CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Authentication
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-04-28
moalmoe moalmoe is offline
Junior Member
 
Join Date: 2007-04-28
Posts: 3
Rep Power: 0
moalmoe has an average reputation (10+)
Default Securid with L2tp and ngx

Hi,

I have set up an ngx r62 fw running on splat.
Created the generic external profile and is authenticating through securid using an rsa ace server.
That part is working great..
I also have a local FW-user that is using a normal FW username/password authentication method, that is also working as expected.

The question is.....can Microsoft Ipsec client (l2tp) be used to connect to the FW, using securid as authentication ??

Tried it with the local FW user, creating the certificate in the user properties for that user in ngx and then importing it on the XP PC. Using MD5-challenge with the FW username/password it worked great.
But there is no way I can create a certificate using the generic profile as I can see. Is this even possible ??
Reply With Quote
  #2 (permalink)  
Old 2007-05-04
moalmoe moalmoe is offline
Junior Member
 
Join Date: 2007-04-28
Posts: 3
Rep Power: 0
moalmoe has an average reputation (10+)
Default Re: Securid with L2tp and ngx

Got it working actually.

I used the certificate generated by another FW-user for the machine to machine connection (probably OK since this is just for the part between the client PC and the firewall).
Then I set up the L2TP client on the XP PC to use PAP as security, then everything worked as it should.
Is it OK to use just PAP or should I change this somehow ??

Thanks..
Reply With Quote
  #3 (permalink)  
Old 2007-05-16
cqliuke cqliuke is offline
Junior Member
 
Join Date: 2006-06-15
Posts: 15
Rep Power: 0
cqliuke has an average reputation (10+)
Default Re: Securid with L2tp and ngx

Hi moalmoe,

Can you tell me how to configure Microsoft Ipsec client (l2tp) ?

I can't configure it successfull.

thanks.
Reply With Quote
  #4 (permalink)  
Old 2007-05-17
Phayder Phayder is offline
Junior Member
 
Join Date: 2007-05-07
Posts: 22
Rep Power: 0
Phayder has an average reputation (10+)
Default Re: Securid with L2tp and ngx

HI cqliuke,

Pay attention on Microsoft VPN, if you dont have version R55, you can not use Automatic NAT on the rules, because GRE is not passing the NAT.

Best Regards,
Phayder
Reply With Quote
  #5 (permalink)  
Old 2007-05-24
moalmoe moalmoe is offline
Junior Member
 
Join Date: 2007-04-28
Posts: 3
Rep Power: 0
moalmoe has an average reputation (10+)
Default Re: Securid with L2tp and ngx

Quote:
Originally Posted by cqliuke View Post
Hi moalmoe,

Can you tell me how to configure Microsoft Ipsec client (l2tp) ?

I can't configure it successfull.

thanks.
I used a whitepaper found on the Checkpoint support pages to set it up...
Reply With Quote
  #6 (permalink)  
Old 2007-07-04
Jay_D Jay_D is offline
Junior Member
 
Join Date: 2007-07-02
Posts: 14
Rep Power: 0
Jay_D has an average reputation (10+)
Default Re: Securid with L2tp and ngx

Hi,

I was able to configure L2TP VPN with a shared secret. I also tried using a certificate and that worked fine too.
I have other users with SecureClient authenticating with SecurID.

However I cannot make this L2TP VPN client to work with SecurID. I have the impression it only works when you use the pre-shared secret located in the encryption tab (select IKE, then authentication tab) and not when you select an authentication method in the authentication tab directly under the user.

But you say you did get this to work with SecurID....so I am very interested in finding out how you did this... I am using R60 but I don't think this makes a difference.

Kind regards,
Jeroen.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 20:11.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0