CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Web Security > Connectra
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-11-09
dharris dharris is offline
Junior Member
 
Join Date: 2006-08-03
Posts: 5
Rep Power: 0
dharris has an average reputation (10+)
Default multiple RADIUS/LDAP domain support

Hi guys
Were setting up a pilot to provide a connectra portal for a parent company with multiple children each with their own AD domain.

I was considering using the RADIUS class attribute to ensure users would be added to the right connectra group (based on the AD user groups) once they authenticate.

My problem is that each AD domain user group will probably have the same group names. Can anyone see a way of getting around this with connectra being used as a single portal for many different domains?

I might have to ditch the centralised option and go for a portal in each AD domain.
Reply With Quote
  #2 (permalink)  
Old 2007-06-12
netktm netktm is offline
Junior Member
 
Join Date: 2006-12-12
Posts: 1
Rep Power: 0
netktm has an average reputation (10+)
Default Re: multiple RADIUS/LDAP domain support

Hi,
I am facing this same problem. We have two diffrents Active Directoy.

And we would like to bind those two domains (with the same appropriate type of group) to use Connectra NGX-61 in the authentification process of users.

We never succed in using these two domains at the same time.

Can somebody tell us how to manage in order to fix this problem ?

Cheers!
Reply With Quote
  #3 (permalink)  
Old 2007-06-12
munrog munrog is offline
Member
 
Join Date: 2006-06-27
Location: New Zealand
Posts: 70
Rep Power: 3
munrog has an average reputation (10+)
Send a message via MSN to munrog Send a message via Skype™ to munrog
Default Re: multiple RADIUS/LDAP domain support

Hi Guys,

Yes we had this problem. It seems that Connectra has problems when there are multiple authentication mechanisms; be they multiple RADIUS servers or say a RADIUS server and a SecurID server.

The only way I have found to get around this problem is to extend the attributes with Firewall-1's attributes - then you can specify which authentication mechanism is used for authenticating which user by modifying the right fw-1 attribute.

I recommend you install an Active Directory Application Mode (ADAM) instance for this.

There is a link from the OPSEC website to performing the ADAM configuration Check Point OPSEC Alliance Partner: Microsoft - Active Directory
and the Check Point manuals tell you how to extend the schema with a standard Active Directory.

The advantage of using ADAM is that you can muck around with it, without ruining your organisations live directory. :o)

Cheers
Greg
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 12:43.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0