CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Authentication
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-09-13
sylaus sylaus is offline
Junior Member
 
Join Date: 2007-09-11
Posts: 2
Rep Power: 0
sylaus has an average reputation (10+)
Default Client Authentication doesn't prompt

Hello, since we made the update to GNX R61 (Build 602000193) I have a problem with the client authentication.
When users click on the browser, sometimes he don`t get the login prompt from my Firewall. It is working for an amount of times and suddenly stop to work.
If I bypass the authentication(opening the rule) it`s work.
My Firewall`s are clustered.(two Nokia ip380)
Any idea ???

Thanks.
Reply With Quote
  #2 (permalink)  
Old 2007-09-28
ngxadmin ngxadmin is offline
Junior Member
 
Join Date: 2007-03-26
Posts: 24
Rep Power: 0
ngxadmin has an average reputation (10+)
Default Re: Client Authentication doesn't prompt

I was just going to create a similiar entry. Since I upgraded from R60 to R62, I have had issues with client authentication. The workaround is to reboot the firewall nodes. Client auth will usually start to fail sporadically after a couple weeks and then pretty much stop working all together. SPLAT - Distributed - Management and 2 enforcement nodes. Had the authentication in place since at least R55 (maybe R54) and there was never an issue.
Reply With Quote
  #3 (permalink)  
Old 2007-09-28
melipla melipla is offline
Senior Member
 
Join Date: 2006-01-25
Posts: 724
Rep Power: 3
melipla has an average reputation (10+)
Default Re: Client Authentication doesn't prompt

I've had flaky Client Auth / User Auth issues in the past, where it work work for a while and then become spotty and eventually stop working. I could temporarily fix the problem by pushing the policy again, but it would stop working after a variable amount of time.

After working with support they told me I had to do a fresh install of SPLAT, since then my Auth issues have not reappeared.

HTH
Reply With Quote
  #4 (permalink)  
Old 2007-09-28
sylaus sylaus is offline
Junior Member
 
Join Date: 2007-09-11
Posts: 2
Rep Power: 0
sylaus has an average reputation (10+)
Default Re: Client Authentication doesn't prompt

Very intersting, do you have more info. about SPLAT ??? It`s mean nothing for me.
Reply With Quote
  #5 (permalink)  
Old 2007-09-30
ngxadmin ngxadmin is offline
Junior Member
 
Join Date: 2007-03-26
Posts: 24
Rep Power: 0
ngxadmin has an average reputation (10+)
Default Re: Client Authentication doesn't prompt

SPLAT is short for Secure Platform. Its kind of an inherent underlying OS that includes the Checkpoint software. I appreciate the entry that melipla made and it rings a bell for me. My node 1 which we normally run from was an upgrade (leaving R60 and R60HFA2 stuff on the box). My node 2 was a format/fresh install. Im going to failover to node 2 this week and see what happens regarding the authentication. Ive heard before that doing a fresh install of a major release is better than trying to do an upgrade.
Reply With Quote
  #6 (permalink)  
Old 2007-10-17
ngxadmin ngxadmin is offline
Junior Member
 
Join Date: 2007-03-26
Posts: 24
Rep Power: 0
ngxadmin has an average reputation (10+)
Default Re: Client Authentication doesn't prompt

After two weeks on node 2, no auth issues. Node 1 probably requires a rebuild/install to alleviate the issue.
Reply With Quote
  #7 (permalink)  
Old 2008-01-31
vandavauk vandavauk is offline
Junior Member
 
Join Date: 2008-01-31
Posts: 1
Rep Power: 0
vandavauk has an average reputation (10+)
Default Re: Client Authentication doesn't prompt

We are having the same issue as well on two different clusters. It started after going to R62 back in August. Currently I am working with Nokia to pin down the issue.

To reiterate the issue:
Users quit getting the popup prompt for authentication, and eventually the session times out and they get a page not found error. All other traffic passes fine. If the same user tries to get to a site that does not require authentication it works fine. If a user is already authenticated when the issue starts, they continue to work fine.

It can be anywhere from a few days to a month before it happens, and it starts with just a few people and then starts to grow rapidly. A “push”, fail over or reboot temporarily resolves the issue.

I have checked memory, CPU and disk usage and I/O on all devices involved (including the Radius server) for any anomalies. Nothing seems to be out of the ordinary. It can happen at times of high traffic or low. I just can’t find any corresponding triggers and nothing is showing up in the logs.

At this moment I am running a continuous capture on our radius server and the next time it happens I hope to prove weather the firewall quits asking, or if the radius server quits replying.

I will post anything new I find…
-Doug

Just an FYI:

Our setup is:
Two clusters running at different locations.

An IP560 (Diskless) cluster (Utilizing VRRP to cluster) running IPSO 4.1 Build 28 and R62 build 620.

An IP380 cluster (Utilizing VRRP to cluster) running IPSO 4.1 Build 28 and R62 build 620.

For Authentication: Funk (now Juniper) Steel Belted Radius
Reply With Quote
  #8 (permalink)  
Old 2008-01-31
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,598
Rep Power: 4
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Client Authentication doesn't prompt

Tell Nokia to escalate this call to Dallas right away. There is an open case that sounds a lot like this to me. Contact me here (PM) if Nokia needs my TAC contact.
Reply With Quote
  #9 (permalink)  
Old 2008-02-08
ngxadmin ngxadmin is offline
Junior Member
 
Join Date: 2007-03-26
Posts: 24
Rep Power: 0
ngxadmin has an average reputation (10+)
Default Re: Client Authentication doesn't prompt

I posted some time ago that I thought I had this resolved with a fresh install of SPLAT on the enforcement node, but that turned out to be incorrect. Eventually it got back to the same issue - no auth prompt. I have to reboot the enforcement node to get it working again. At least 3 checkpoint cases, no resolution.
Reply With Quote
  #10 (permalink)  
Old 2008-02-08
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,598
Rep Power: 4
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Client Authentication doesn't prompt

If this is an immediate problem for anyone please contact me directly.

When there is a fully tested and approved fix, I will report it here.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 17:10.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0