CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Authentication
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-12-03
devil_i devil_i is offline
Junior Member
 
Join Date: 2007-07-30
Location: Minsk, Belarus
Posts: 6
Rep Power: 0
devil_i has an average reputation (10+)
Send a message via ICQ to devil_i
Default Client authentication and Windows logon/logoff

I want to use benefits of client authentication but only during the one windows session. When user log off from workstation and another user log on it must be requested to authenticate. Is it possible with such type of authentication?
Reply With Quote
  #2 (permalink)  
Old 2007-12-03
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 857
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: Client authentication and Windows logon/logoff

Client Authentication authenticates the machine, not the user.

You may want too look at Session Authentication which will auth the session rather than the machine.

Also if you have the budget then I believe that User Authority is the product that really does what you are looking for in that allows much easier link in with the Windows Username. I don't believe that Session Auth will actually link in with Windows.
Reply With Quote
  #3 (permalink)  
Old 2007-12-03
devil_i devil_i is offline
Junior Member
 
Join Date: 2007-07-30
Location: Minsk, Belarus
Posts: 6
Rep Power: 0
devil_i has an average reputation (10+)
Send a message via ICQ to devil_i
Default Re: Client authentication and Windows logon/logoff

Yes, i know that such type of authentication rely on machine, but what about limits? number of sessions and timeout. Can these properties be used?
Reply With Quote
  #4 (permalink)  
Old 2007-12-03
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 857
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: Client authentication and Windows logon/logoff

The client is not unauthenticated just because the user logs off. As such unless you logoff and the client auth then times out if another user logs in then they won't be asked to authenticate again until the timeout kicks in.

Client auth doesn't use sessions as such so I don't believe that it will do what you want.
Reply With Quote
  #5 (permalink)  
Old 2007-12-03
BarryStiefel BarryStiefel is offline
Administrator
 
Join Date: 2005-08-11
Location: San Francisco, CA
Posts: 534
Rep Power: 10
BarryStiefel has disabled reputation
Default Re: Client authentication and Windows logon/logoff

Quote:
Originally Posted by mcnallym View Post
Client Authentication authenticates the machine, not the user.

You may want too look at Session Authentication which will auth the session rather than the machine.

Also if you have the budget then I believe that User Authority is the product that really does what you are looking for in that allows much easier link in with the Windows Username. I don't believe that Session Auth will actually link in with Windows.
Actually, Client Authenticates the IP address, not the specific machine. If a bunch of you are hiding behind a single IP address, authenticating one of you authenticates all of you.
__________________
Barry J. Stiefel ("Stee-ful")
CCSA/CCSE/CCSE+/CCSI
President, CPUG
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 19:41.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0