CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Authentication
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-05-02
robertvg robertvg is offline
Junior Member
 
Join Date: 2005-11-28
Posts: 4
Rep Power: 0
robertvg has an average reputation (10+)
Default two factor authentication using SMS

I'm looking for a way to send an authentication code to a user using SMS text messages that he can then use to login to a Checkpoint VPN.
Did anybody ever implement such solution ?
Reply With Quote
  #2 (permalink)  
Old 2007-05-03
munrog munrog is offline
Member
 
Join Date: 2006-06-27
Location: New Zealand
Posts: 70
Rep Power: 3
munrog has an average reputation (10+)
Send a message via MSN to munrog Send a message via Skype™ to munrog
Default Re: two factor authentication using SMS

I have succesfully trialled both PortWise and Swivel as products to provide SMS authentication to Connectra clients. Also tried Firewall-1 and that worked to. Basically these both work as multiple Challenge radius. You may need to tell the Check Point to ignore some additional extended attributes. This is simple enough in the SmartDashboard GUI, but you may find it easier to resort to dbedit and enter multiple extended attribute values as elements.

The Portwise was much easier for the end users as it was a simple alphanumeric sequence.

Whereas Swivel sent an SMS that had a legend, a blank line and then a key which looked like this

1 2 3 4 5 6 7 8 9

w X ! 8 6 n R q m


With Swivel you have a personal identification number eg "3672", which from the above SMS would translate to a password of "!nRX". But because of the way it displayed the legend on the top then a blank line, then the authentication string with some randomised chars, it was very hard for the brain to get around and the users hated it.

hope this helps
Greg
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 19:52.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0