CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Certifications And Exams > CCSA (Check Point Certified Security Administrator) > CCSA NGX Exam 156-215.1
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-01-29
Junior Member
 
Join Date: 2006-11-04
Posts: 9
Rep Power: 0
cetta has an average reputation (10+)
Default What is the correct answer?

You are the security administrator for Certkiller.com. Certkiller's security policy forces users to authenticate to the secuity gateway explicitly, before they can use any service. You are also reminded that your gateway does not allow the Telnet service to itself any location. How would you set up the authentication method?

A. With a client authentication rule using the manual sign-on method, using HTTP on port 900
B. With a Session Authentication Rule
C.With Client Authentication rule for Partially Automatic Sign-On
D.With a Client Authentication for fully automatic sign-on
E.With a User Authentication Rule

Testking says correct answer is A. I think B, because manual sign on using http or telnet and client authentication rule must be placed above the stealth rule. As for you what is the correct answer?
Reply With Quote
  #2 (permalink)  
Old 2007-01-29
Member
 
Join Date: 2006-10-16
Location: Brisbane, Australia
Posts: 92
Rep Power: 3
godspeedcapri has an average reputation (10+)
Default Re: What is the correct answer?

The answer 'A' seems most appropriate as users are expected to sign on explicitly(hence manual sign on method), to access firewall the rule has to be placed above stealth rule(where you specify who will connect using what service(http port900).

Configuring Client Authentication in the Rulebase


To allow client authentication, create a new rule above any rule that would block
ports 900 and 259 to the firewall (usually the Stealth Rule). In the source field,
select Add User Access, and then add the user group that will be able to authenticate,
and optionally restrict to a location, where that group can connect from.

Pg:314 Syngress CCSA NGX Book

Cheers,
Godspeedcapri
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 00:18.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0