CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Authentication
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-11-28
paolo.piombino paolo.piombino is offline
Junior Member
 
Join Date: 2007-10-22
Posts: 12
Rep Power: 0
paolo.piombino has an average reputation (10+)
Default http user auth does not work

I have the following problem with user authentication specifically with http
i create a rule that allow http traffic from inside network to outside with user authentication but i cannot surf because the authentication fail 3 times!
the user and password are correct and local authentication is enabled on CheckPoint.
I use SecurePlatform NGX R60
Reply With Quote
  #2 (permalink)  
Old 2007-11-28
RobertGraham RobertGraham is offline
Senior Member
 
Join Date: 2006-02-02
Posts: 204
Rep Power: 3
RobertGraham has an average reputation (10+)
Send a message via MSN to RobertGraham Send a message via Yahoo to RobertGraham
Default Re: http user auth does not work

Try resetting the user's password and re-pushing the policy.
Reply With Quote
  #3 (permalink)  
Old 2007-11-29
paolo.piombino paolo.piombino is offline
Junior Member
 
Join Date: 2007-10-22
Posts: 12
Rep Power: 0
paolo.piombino has an average reputation (10+)
Default Re: http user auth does not work

done but the same result
Reply With Quote
  #4 (permalink)  
Old 2007-11-29
RobertGraham RobertGraham is offline
Senior Member
 
Join Date: 2006-02-02
Posts: 204
Rep Power: 3
RobertGraham has an average reputation (10+)
Send a message via MSN to RobertGraham Send a message via Yahoo to RobertGraham
Default Re: http user auth does not work

Is this on SPLAT? If so, are there any OS logs that show anything valuable?

What HFA is this?

Otherwise, I'd try doing a tcpdump to see what's going over the wire. Do binary output and open it up in wireshark.
Reply With Quote
  #5 (permalink)  
Old 2007-11-30
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 355
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: http user auth does not work

Things to check:
- Move authentication rule as close to the top of the rulebase as possible
- User expiration date (under "Personal")
- The group the user belongs to
- Authentication Scheme should be "Check Point Password"
- User Auth rule has source as "User group"@"Intenal Network"
- User Auth properties "Http all servers" (right click "user auth" action on the rule)

Make sure you push the policy and just to be safe, Install the user database too "Policy->Install database"
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 20:11.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0