CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We've already had our first sign-ups!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 6/9, 7/14, 8/25, 10/6, 11/3, 12/8.
3. We have new forums in Portuguese and German (see below).
4. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
5. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Authentication
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-02-08
sivakumar sivakumar is offline
Junior Member
 
Join Date: 2007-12-27
Posts: 3
sivakumar has an average reputation (10+)
Default Merits and Demerits of Checkpoint Authentication Methods

Hi,

My client needs to implement AD intergration to checkpoint now running R60 and planning to upgrade R62. now the authentican used is by certificates.

anyone can point some documents relating to merits and demerits of checkpoint authentication methods and which one is more secure.

thanks

siva
__________________
sivakumar
Reply With Quote
  #2 (permalink)  
Old 2008-02-14
vijayant vijayant is offline
Member
 
Join Date: 2006-05-24
Posts: 90
vijayant has an average reputation (10+)
Default Re: Merits and Demerits of Checkpoint Authentication Methods

User Authentication is more secure as compared to Client and session authentication. But it all depends on your setup whic option can suit better.
Reply With Quote
  #3 (permalink)  
Old 2008-02-14
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 834
RayPesek has an average reputation (10+)
Default Re: Merits and Demerits of Checkpoint Authentication Methods

What are they authenticating for? If it's remote access, certificates are far more secure than user name and password. Anything based solely on user name and password is insecure.

Ray
Reply With Quote
  #4 (permalink)  
Old 2008-02-15
lodown lodown is offline
Member
 
Join Date: 2006-05-05
Posts: 51
lodown has an average reputation (10+)
Default Re: Merits and Demerits of Checkpoint Authentication Methods

While I agree that using certificates is a more secure method of authentication, they are also more difficult to manage in a large environment. I migrated a previous company from certificates to Active Directory because of this. Internal users would leave, often in offices that had little centralized process for terminations. Clients or business partners needed VPN access to specific applications in scenarios that did not fit in to a site-site VPN. Because AD was already a part of the termination process, we felt there was better control of access to internal and DMZ resources. We were also able to hand over user management from the firewall/networking team to regional resources without giving them access to the firewall management system. Lastly, password management was better. Our Password policy in AD was already 90 days. With certificates we had no way to force users to change their passwords on a regular basis, another security risk.

If I had my choice I would have preferred to use RSA SecurID, but the cost was prohibitively expensive. I feel that in this case, putting controls around a less secure authentication method was more secure than using certificates.

lodown
Reply With Quote
  #5 (permalink)  
Old 2008-02-15
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 834
RayPesek has an average reputation (10+)
Default Re: Merits and Demerits of Checkpoint Authentication Methods

Some valid points to be sure, particularly if the termination process is flawed.

There's really no reason to change a certificate password, which is actually the private key and would require a new certificate, because you need to be in possession of the certificate as well as the password to compromise a system.

It would be nice if we could use certificates in conjunction with AD.

Ray
Reply With Quote
  #6 (permalink)  
Old 2008-02-28
sivakumar sivakumar is offline
Junior Member
 
Join Date: 2007-12-27
Posts: 3
sivakumar has an average reputation (10+)
Default Re: Merits and Demerits of Checkpoint Authentication Methods

Really what lodown expressed is my site scenario, no control on VPN user id termination process. Already we have well built two domains for internal and dealers, and if AD to be integrated, i will use two ldap databases for internal vpn and dealers services access. As well said finally AD and certficate intergarted authentication will give best results, considering business needs, i feel as above.

thanks for all posted for my query.
__________________
sivakumar
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 22:09.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0