CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We've already had our first sign-ups!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 6/9, 7/14, 8/25, 10/6, 11/3, 12/8.
3. We have new forums in Portuguese and German (see below).
4. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
5. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Authentication
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-03-13
microIT microIT is offline
Junior Member
 
Join Date: 2008-03-13
Posts: 1
microIT has an average reputation (10+)
Default Outlook Anywhere Filter by SmartDirectory Computer objects

we are thinking about using outlook anywhere but need to somehow restrict it to only pcs that are company pcs (AD objects) attaching to the server externally. we use checkpoint ngx r65 and have smart directory.

what would be nice is to have the rules say "LDAP Group" which is really the Organizational Unit for computer objects as the source and our CAS Exchange box as the destination, https as the service... I can't do a typical "Accept" for action due to authentication rules do not allow that. The source works fine with "Any" but we are looking for more information on how to only allow if the user is using a computer which is an object in the domain or part of that LDAP group. Is this even possible? Any suggestions at all are greatly appreciated. Feel free to ask more questoins back to obtain the proper detail needed.

Last edited by microIT : 2008-03-13 at 20:35.
Reply With Quote
  #2 (permalink)  
Old 2008-03-14
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 791
mcnallym has an average reputation (10+)
Default Re: Outlook Anywhere Filter by SmartDirectory Computer objects

This is what Integrity/End Point Security is for.

With this you can check the machine for a registry entry, or a file to ensure that the machine is a corporate machine.

SMARTDirectory is only for User Groups in LDAP, it won't do groups that aren't users.
Reply With Quote
  #3 (permalink)  
Old 2008-03-14
dsb.nepo dsb.nepo is offline
Senior Member
 
Join Date: 2006-04-30
Location: Europe, Germany
Posts: 112
dsb.nepo has an average reputation (10+)
Default Re: Outlook Anywhere Filter by SmartDirectory Computer objects

I don't know if this is possible but maybe ...

- Setup Windows CA
- role out certs for computer (not exportable)
- create auth rule wich asks for the computer (and user) cert.

If you switch to Microsoft IPSec/L2TP the machine and the user needs a cert.

Problem for verify Reg. values and other parameters is that technical users can track this down with regmon, filemon ...
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 23:26.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0