CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Web Security > Connectra
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-04-24
juergen juergen is offline
Junior Member
 
Join Date: 2006-04-24
Posts: 2
Rep Power: 0
juergen has an average reputation (10+)
Default NTLMv2

Hi there,
we've got a win2k3 ad domain and I've noticed that ntlmv2 with connectra does not work!! FileSharing and WebApplications don't work from connectra. After several unsuccessful tries the account gets locked out. as the software comes with samba 2.2.7 is there a chance to get it work with NTLMv2. I don't want to switch back to old NT times....


thank you!
Reply With Quote
  #2 (permalink)  
Old 2006-04-24
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 873
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: NTLMv2

How do you have Connectra set up for authentication?

Have you looked at the release notes for Connectra NGX R61, which was put on the download site a week or two ago? They did some work on some authentication issues, but I don't recall precisely what it was.

Ray
Reply With Quote
  #3 (permalink)  
Old 2006-04-25
juergen juergen is offline
Junior Member
 
Join Date: 2006-04-24
Posts: 2
Rep Power: 0
juergen has an average reputation (10+)
Default Re: NTLMv2

Sorry I’ve forgotten to mention that we are using the newest version NGX R61. Authentication is done with certificates (PKI) or one time passwords with RADIUS. The Authentication works fine, no problem at all. However if the logged in user tries to access a file share on a win2k3 fileserver or a web resource with NTLM access fails…
In the evnetlog on the windows file server you’ll see the follwing error message:
Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 529
Date: 25.04.2006
Time: 19:28:38
User: NT AUTHORITY\SYSTEM
Computer: NAMEOFMYSERVER
Description:
Logon Failure:
Reason: Unknown user name or bad password
User Name: USERNAME---
Domain: DOMAINMAE--
Logon Type: 3
Logon Process: NtLmSsp
Authentication Package: NTLM
Workstation Name: \\IP of connectra
Caller User Name: -
Caller Domain: -
Caller Logon ID: -
Caller Process ID: -
Transited Services: -
Source Network Address: IP of connectra
Source Port: 0


For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Reply With Quote
  #4 (permalink)  
Old 2006-05-03
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 873
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: NTLMv2

Are you by any chance trying to use multiple Windows domains? Here's what I had:

Windows IAS server was in domain "A"

User was in domain "B" and file share was in domain "B" with a two-way trust to "A"

For granularity, I created the user in Connectra as "B\user" with RADIUS to the IAS server.

Virtually everything worked except for file shares. It gave me an unknown user message. A packet capture showed the authentication traffic was being passed to the file share as "A\B\user"

The only fix was to leave the file share field "Windows default domain" blank AND configure the share to prompt for credentials rather than passing the portal credentials.

Check Point came up with this workaround. They said I should have set up the user as "generic*" and used RADIUS groups to handle the access rules, but they also said we lose granularity with that solution, which is why we didn't do it.

Ray
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 11:35.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0