CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We've already had our first sign-ups!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 6/9, 7/14, 8/25, 10/6, 11/3, 12/8.
3. We have new forums in Portuguese and German (see below).
4. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
5. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Authentication
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-02-21
haubera haubera is offline
Junior Member
 
Join Date: 2008-02-12
Posts: 4
haubera has an average reputation (10+)
Default Check Point Came trough and FIXED IT

So you all remember my Issue with not Authenticating @ all times for my Users. Workaround was to telnet and authentication came up. Well Oli from Checkpoint fixed it and the fix was very easy!!! the fix is below!!1 This worked for me so i'am not saying it workes for everyone but after 4 weeks working with the TS Team and not being able to figure out the issue which i have to say their TS team is very good at what the do. So try it if it works be happy

1. We can launch additional security server daemons if necessary. We can do it by editing $FWDIR/conf/fwauthd.conf on the ENFORCEMENT module:
-- ssh to the firewall enforcement module
-- # cd $FWDIR/conf
-- # vi fwauthd.conf
-- change the line: 80 fwssd in.ahttpd wait 0
to: 80 fwssd in.ahttpd wait -4
( the -4 indicates actually we will launch 4 processes if necessary)
-- save and exit the file, then performn step 2 and 3.

2. We can increase the max number of redirected http connections. This requires closing SmartDashboard GUI and using another program called "GUIDBEdit.exe"
-- on your GUI client machine, go to C:\Program Files\CheckPoint\SmartConsole\R65\PROGRAM\
-- launch the program GuiDBedit.exe, and login to the Management server IP using your Firewall admin user
-- go to the Search menu, and click on "Find" and search for:
http_max_auth_redirect_num
-- whenever it finds the value, double click it and change it from "1000" to "2000"
-- in the File menu click on "Save all"
-- open SmartDashboard and install the policy on the firewall enforcement module.

3. restart the firewall enforcement module in order to launch the security server with the new configuration:
-- run #cpstop;cpstart
Reply With Quote
  #2 (permalink)  
Old 2008-03-05
IndyBoiler IndyBoiler is offline
Junior Member
 
Join Date: 2007-04-16
Posts: 9
IndyBoiler has an average reputation (10+)
Default Re: Check Point Came trough and FIXED IT

What was your original problem? Did you have in.ahttpd daemons that would hang? or users that were not getting prompted for authentication?
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 22:23.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0