CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Authentication
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-02-22
aallsopp aallsopp is offline
Junior Member
 
Join Date: 2005-10-31
Location: Saskatoon, Saskatchewan, Canada
Posts: 27
Rep Power: 0
aallsopp has an average reputation (10+)
Default No pop-up using Client Auth

Two Nokia IP350 gateways. One here in Saskatoon and a new install in New Brunswick. Both running IPSO 4.0 and NGX. Centrally managed from Saskatoon. Site to site VPN between two gateways is functioning properly. Client Auth works in Saskatoon.
Voyager is using https and the http port has been changed to 8080.
Manual client auth using http://gateway-address:900 works and RADIUS works. Tracker shows all activity as allowed.
When you just enter an outside URL you just get a page cannot be found error. Tracker shows http going to gateway address but that's all. Disabling client auth gives access to the internet.

Any ideas to try out? the ones in Checkpoints Solution ID: #sk12072 did not work.
Reply With Quote
  #2 (permalink)  
Old 2006-02-23
Lackie Lackie is offline
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 3
Lackie has an average reputation (10+)
Default Re: No pop-up using Client Auth

Do you have DNS set up on the enforcement point?
Reply With Quote
  #3 (permalink)  
Old 2006-02-24
aallsopp aallsopp is offline
Junior Member
 
Join Date: 2005-10-31
Location: Saskatoon, Saskatchewan, Canada
Posts: 27
Rep Power: 0
aallsopp has an average reputation (10+)
Default Re: No pop-up using Client Auth

Yes, DNS is set up.
Primary DNS is the internal DNS server.
Secondary DNS is corprate DNS at main site (trough VPN).
Tertiary DNS is DNS supplied by ISP providing Internet Line.
As long as semi-automatic client auth is not used, everything works.

Last edited by aallsopp; 2006-02-24 at 08:37.
Reply With Quote
  #4 (permalink)  
Old 2006-03-13
aallsopp aallsopp is offline
Junior Member
 
Join Date: 2005-10-31
Location: Saskatoon, Saskatchewan, Canada
Posts: 27
Rep Power: 0
aallsopp has an average reputation (10+)
Default Re: No pop-up using Client Auth

I set up a new rule with a user defined service containing the following macro

CLNTAUTH_MUST_FOLD(##)

where ## is the client authentication rule number. It works now.

Nokia is saying that there may be some corrupt or missing files in our firewall setup, but since it is 3000 miles away, I think I will wait until a scheduled trip to try a re-install.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 20:16.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0