CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Authentication
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-11-13
Junior Member
 
Join Date: 2005-12-27
Posts: 4
Rep Power: 0
isrmail69 has an average reputation (10+)
Default user auth problem

Hi
I need some help to make the right answer to my company CTO.
The problem is to secure Wi-Fi access without money.
The idea is:
1. Put the access point behind the FW (ngx 62) interface
2. Create user group with generic* only member.
3. Connect to Radius authentication (already exist and working good with VPN)
4. Create rule like:
Wi-Fi_Radius@SourceNetwork / Dest Network / all_needed_protocols / User_Auth / Log
5. User will connect from SourceNetwork , pass Radius auth and get resources with no more user intervention.
6. Unknown user will be stopped by authentication.
This is the scenario.
After some check I get user authentication but every second get auth prompt
And get errors installation policy when add protocols.
I think that user auth not support protocols other then: http rlogon ftp telnet.
So it wills not work normally like get connected inside the network.
Please response to my problem
Regards
Reply With Quote
  #2 (permalink)  
Old 2007-11-14
Senior Member
 
Join Date: 2006-01-25
Posts: 926
Rep Power: 3
melipla has an average reputation (10+)
Default Re: user auth problem

From the Check Point Online Help in my R65 Smart Dashboard client:

Quote:
The VPN-1 Solution for Authentication

User Authentication: Enables administrators to permit users who have temporarily left their desk to work on the local network without extending access to all users on the same host. User authentication is available only for the Telnet, FTP, HTTP and RLOGIN services.
Specific client auth configurations have the same limitation.

HTH
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 16:33.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0