CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Miscellaneous > Feedback To Check Point: Suggestions And Requests
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-10-06
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 913
Rep Power: 3
RayPesek has an average reputation (10+)
Default Allow the Edge SSL certificate to be replaced

The Edge "hotspot" feature is nice as long as you force SSL to protect the traffic. Unfortunately it uses a self-signed certificate and there's no way to install a real certificate.

We train our users to not use sites with self-signed certificates, so we cannot offer the hotspot feature, which we really want to do.

We never use https://my.vpn, my.firewall or my.hotspot, so we don't really care about the certificate mismatch it would cause. We would use a certificate of hotspot.ourcompany.com for the Edge if we could do it.

Ray
Reply With Quote
  #2 (permalink)  
Old 2006-10-09
Senior Member
 
Join Date: 2006-01-25
Posts: 1,004
Rep Power: 4
melipla has an average reputation (10+)
Default Re: Allow the Edge SSL certificate to be replaced

Good one.

I vote for configurable MAC Addresses for Edge interfaces. Last code rev I checked, LAN1 LAN2 LAN3 LAN4 all used the same MAC.
__________________
Its all in the documentation.
Reply With Quote
  #3 (permalink)  
Old 2006-10-11
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,681
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Allow the Edge SSL certificate to be replaced

Quote:
Originally Posted by melipla View Post
I vote for configurable MAC Addresses for Edge interfaces. Last code rev I checked, LAN1 LAN2 LAN3 LAN4 all used the same MAC.
LAN1-4 is a switch not seperate interfaces so they all have the same MAC (that of the switch).
Reply With Quote
  #4 (permalink)  
Old 2006-10-12
Senior Member
 
Join Date: 2006-01-25
Posts: 1,004
Rep Power: 4
melipla has an average reputation (10+)
Default Re: Allow the Edge SSL certificate to be replaced

Quote:
Originally Posted by chillyjim View Post
LAN1-4 is a switch not seperate interfaces so they all have the same MAC (that of the switch).
Hence the feedback for them to have seperate MAC addreses....

Inside the Edge web-based configuration they look like seperate interfaces, not only in their labeling but regarding which VLAN they're in. Normal switches are able to have different MACs on their interfaces.
__________________
Its all in the documentation.
Reply With Quote
  #5 (permalink)  
Old 2006-10-13
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,681
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Allow the Edge SSL certificate to be replaced

Minor Rant

This is where the definition of a switch has changed. A switch port is is a bridge and and in-and-of itself doesn't have a MAC address, a manageable switch will have a MAC (so you can telent and the like to it). Now we have this concept of a layer-3 switch, which is switch/router combination and a port may act as a routed port and as such needs a MAC address.

Most of this terminology problems are directly Cisco's fault. Cisco even has a different definition for a router and bridge than what they were when we started (Bridges connect two or more physical networks, routers connect two or more logical networks. Cisco routers are brouters, bridging-routers)

/Rant (A sore point of mine)
Reply With Quote
  #6 (permalink)  
Old 2006-10-13
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,681
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Allow the Edge SSL certificate to be replaced

Quote:
Originally Posted by RayPesek View Post
The Edge "hotspot" feature is nice as long as you force SSL to protect the traffic. Unfortunately it uses a self-signed certificate and there's no way to install a real certificate.
VPN->Certificate->Install Certificate
Reply With Quote
  #7 (permalink)  
Old 2006-10-14
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 913
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Allow the Edge SSL certificate to be replaced

Thanks. Will that let you select which certificate you want to replace? Seems to me there's my.firewall, my.vpn and my.hotspot certificates, but my memory could be faulty (again).

I'll poke around with that next week and let you onow how it goes.

Ray
Reply With Quote
  #8 (permalink)  
Old 2006-10-17
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,681
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Allow the Edge SSL certificate to be replaced

Quote:
Originally Posted by RayPesek View Post
Thanks. Will that let you select which certificate you want to replace? Seems to me there's my.firewall, my.vpn and my.hotspot certificates, but my memory could be faulty (again).
There is only one from what i'm told.

Quote:
I'll poke around with that next week and let you onow how it goes.

Ray
Please do.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 01:26.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0