CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Authentication
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-06-12
hotice_ hotice_ is offline
Senior Member
 
Join Date: 2007-06-05
Location: Montreal,Canada
Posts: 129
Rep Power: 2
hotice_ has an average reputation (10+)
Default Cannot use HTTPs service with USER AUTHENTICATION

Hi,
I'm having trouble using the HTTPs service with a USER authentication rule.

HTTP works fine i get prompted for a l/p but as soon as I switch to HTTPS, i get absolutely nothing, and nothing in the tracker either


Using NGX R62 on IPSO 4.1 build 25

There is a solution on the SecureKnowledge but its for an older NG AI 55 version (although I DID try to implement the solution without success)

anyone?

Last edited by hotice_; 2007-06-12 at 17:10.
Reply With Quote
  #2 (permalink)  
Old 2007-06-14
melipla melipla is offline
Senior Member
 
Join Date: 2006-01-25
Posts: 724
Rep Power: 3
melipla has an average reputation (10+)
Default Re: Cannot use HTTPs service with USER AUTHENTICATION

Try to use a seperate rule for your https user auth rule [ie so there's only https listed as a service].

In Smartview Tracker you may not see the user auth logs after the initial auth if you're filtering on rule number, as subsequent matches for a user auth rule do not log the rule number that it matches.

Have you ever set up HTTPS userauth and had it work? On your management server, in $FWDIR/conf/fwauthd.conf do you have a line that starts with 443?

Which SK are you referring to?

Lastly, in some cases I've had better luck with a "Partially Automatic Client Auth" instead of using user auth.
Reply With Quote
  #3 (permalink)  
Old 2007-12-09
jamesliao jamesliao is offline
Junior Member
 
Join Date: 2006-01-08
Posts: 4
Rep Power: 0
jamesliao has an average reputation (10+)
Default Re: Cannot use HTTPs service with USER AUTHENTICATION

As I know https was not support on user authentication in old version, I am not sure does it supoort on NGX version ?
Reply With Quote
  #4 (permalink)  
Old 2007-12-10
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 346
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Cannot use HTTPs service with USER AUTHENTICATION

I wasn't aware that User Auth also supported HTTPS. I found the file you mentioned (sk14340).

You could always follow melipla's suggestion and do Client Auth with the Automatic bit.

Also, I'd be wary of using authentication if the credentials are sent in clear text, you should check that too.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 17:01.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0