CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Internal Security > Endpoint Security (Formerly Integrity)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-04-26
arifkm786 arifkm786 is offline
Junior Member
 
Join Date: 2006-05-03
Posts: 18
Rep Power: 0
arifkm786 has an average reputation (10+)
Default Stopping/shutting down Integrity agent to overcome SCV check failures

Hi,
I wanted to find a way to stop users with local administrator priv on their m/c from stopping/shutting down the Integrity client/agent before using the secure client to connect using vpn.

They are doing this so that even if their m/cs fail compliance their vpn connection is not blocked as integrity agent is not running. So they are able to access the internal resources...

In essence they are circumventing the whole idea by shutting down integrity agent and just using secure client.

As long as integrity client and secure client are running and compliance check fails , their connections are blocked by integrity agent on non-compliance ...


Are there any work arounds pls

Thnx

-Arif
Reply With Quote
  #2 (permalink)  
Old 2007-04-27
betski betski is offline
Member
 
Join Date: 2006-07-05
Location: Yorkshire, UK
Posts: 42
Rep Power: 0
betski has an average reputation (10+)
Default Re: Stopping/shutting down Integrity agent to overcome SCV check failures

Are you using integrity flex or agent? flex gives user all rights.

if agent try this-
policy > client settings tab > untick 'permit user to shut down client'
Reply With Quote
  #3 (permalink)  
Old 2007-04-27
arifkm786 arifkm786 is offline
Junior Member
 
Join Date: 2006-05-03
Posts: 18
Rep Power: 0
arifkm786 has an average reputation (10+)
Default Re: Stopping/shutting down Integrity agent to overcome SCV check failures

Thanx for your reply. I have already un-checked that option which says

"permit user to shut down client when enterprise policy is active" . This will not allow the user to shutdown integrity agent while you are connected to vpn .

The problem is they are shutting integrity agent even before connecting to VPN via secure client.

so when they start secure client for connection, integrity agent is already disabled/shut down.


Is there a way to prevent this(may be i will create another policy which is in affect while user is disconnected from vpn and enable the above setting and see) .

any ideas or workarounds would be appreciated.

Thnx
Reply With Quote
  #4 (permalink)  
Old 2007-05-11
dingo8mybaby dingo8mybaby is offline
Junior Member
 
Join Date: 2006-08-23
Location: Europe
Posts: 18
Rep Power: 0
dingo8mybaby has an average reputation (10+)
Send a message via ICQ to dingo8mybaby
Default Re: Stopping/shutting down Integrity agent to overcome SCV check failures

Are you using a disconnected policy and connected policy?

In our disconnected policy we have these options selected
'Enforce this policy when client is disconnected.'

and this unselected 'Permit user to shut down client when enterprise policy is active.'

That means that our users can't shut the agent down - even the ones with full admin accounts. I have found a way to shut the client down that works around this, but it's not a straight forward approach.
Reply With Quote
  #5 (permalink)  
Old 2007-05-16
arifkm786 arifkm786 is offline
Junior Member
 
Join Date: 2006-05-03
Posts: 18
Rep Power: 0
arifkm786 has an average reputation (10+)
Default Re: Stopping/shutting down Integrity agent to overcome SCV check failures

Can you share the work around ? Task Mgr denies access when you try to shutdown the iclient.exe when the disconnected policy is in place

Thnx
Reply With Quote
  #6 (permalink)  
Old 2007-05-21
RobertGraham RobertGraham is offline
Senior Member
 
Join Date: 2006-02-02
Posts: 204
Rep Power: 3
RobertGraham has an average reputation (10+)
Send a message via MSN to RobertGraham Send a message via Yahoo to RobertGraham
Default Re: Stopping/shutting down Integrity agent to overcome SCV check failures

There's also an option to remove the icon from the systray. This makes it a little harder for unwitting users to shut it down.
Reply With Quote
  #7 (permalink)  
Old 2007-06-05
dingo8mybaby dingo8mybaby is offline
Junior Member
 
Join Date: 2006-08-23
Location: Europe
Posts: 18
Rep Power: 0
dingo8mybaby has an average reputation (10+)
Send a message via ICQ to dingo8mybaby
Default Re: Stopping/shutting down Integrity agent to overcome SCV check failures

Quote:
Originally Posted by arifkm786 View Post
Can you share the work around ? Task Mgr denies access when you try to shutdown the iclient.exe when the disconnected policy is in place

Thnx

boot into safemode, rename the checkpoint app folder to checkpoint1 and then reboot. This is the only way I have found to stop it loading on our client systems where we don't allow end users to shut the client down. Under older versions you could use msconfig, but not with v6/6.5

Obviously for this you'll need the local Admin account deatils for the system.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 08:02.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0