CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Internal Security > Endpoint Security (Formerly Integrity)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-11-22
jameshill jameshill is offline
Junior Member
 
Join Date: 2005-08-21
Posts: 2
Rep Power: 0
jameshill has an average reputation (10+)
Default SCV issue with Integrity

Not sure if anyone has experienced this issue, but I thought that I would ask. I have configured a firewall for SecureClient and I have setup my local.scv file to check for the Integrity client. I have also modified my Global Properties to not allow connectivity to the VPN if the SCV check fails. In order that the
SecureClient can communicate with the Integrity Server, there
has to be a rule on the FW that allows unverified communication between
the Client and the Server in order to recieve policy etc.
I created 3 new services for unverified http, https and Zoneprotocol as
described in the guide.
The new services look like this:

- Service of type other
- protocol 6
- match dport=80, r_scvres=SCV_DONT_VERIFY

The same was done for https - dport=443
and the service for zoneprotocol has protocol 17 and dport=6054.

When I try to install the policy, however, I get the following errors:

"/opt/CPfw1-R55p/conf/Standard_11_18_2005_1.pf", line 3136: ERROR: cannot find <http_wo_scv> anywhere

"/opt/CPfw1-R55p/conf/Standard_11_18_2005_1.pf", line 2623: ERROR: syntax error


Has anyone seen this before?
Reply With Quote
  #2 (permalink)  
Old 2006-05-04
arifkm786 arifkm786 is offline
Junior Member
 
Join Date: 2006-05-03
Posts: 18
Rep Power: 0
arifkm786 has an average reputation (10+)
Default Re: SCV issue with Integrity

what version of checkpoint are you running? FYI,checkpoint NG R55 AI doesnt work with Integrity Server 6.0.
Reply With Quote
  #3 (permalink)  
Old 2006-05-09
cettinger cettinger is offline
Junior Member
 
Join Date: 2006-04-21
Posts: 1
Rep Power: 0
cettinger has an average reputation (10+)
Default Re: SCV issue with Integrity

Hi James,

we ran into the same problem using NGX R60, wasting quite some time following the instructions in the documentation. Finally we discovered that there's a button under Policy/Global Properties/Remote Access/Secure Configuration Verification (SCV) right behind the "Apply SCV on Simplified mode ..." checkbox called "Exceptions...". Pressing this button and entering your Integrity Server as a host with the services http, https and ZSP should do the trick. The rules mentioned in the documentation are not required. My guess is that for this feature the documentation isn't up-to-date.

Hope that helps, Christian

Last edited by cettinger; 2006-05-11 at 06:14. Reason: Typos
Reply With Quote
  #4 (permalink)  
Old 2006-05-10
jameshill jameshill is offline
Junior Member
 
Join Date: 2005-08-21
Posts: 2
Rep Power: 0
jameshill has an average reputation (10+)
Default Re: SCV issue with Integrity

Yeah, this Exceptions tab didn't exist under R55.

Thanks guys
Reply With Quote
  #5 (permalink)  
Old 2006-06-20
Uriel Uriel is offline
Junior Member
 
Join Date: 2006-06-20
Posts: 1
Rep Power: 0
Uriel has an average reputation (10+)
Default Re: SCV issue with Integrity

Hi,

In older version i dont know, but in R61, in match field, if you put:
dport=80, set r_scvres SCV_DONT_VERIFY
It works.

Hope that helps, and i will try the sugestion of cettinger.
Reply With Quote
  #6 (permalink)  
Old 2006-09-05
Steve Steve is offline
Junior Member
 
Join Date: 2006-05-02
Posts: 24
Rep Power: 0
Steve has an average reputation (10+)
Default Re: SCV issue with Integrity

if you use the combined install of secure client and integrity - do you still have to configure your scv checks on the checkpoint gateway?

thanks.
Reply With Quote
  #7 (permalink)  
Old 2006-09-05
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,648
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: SCV issue with Integrity

Yes you do.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 02:18.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0