CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-03-14
Junior Member
 
Join Date: 2007-03-13
Posts: 11
Rep Power: 0
JPK300 has an average reputation (10+)
Default Client Authentication rule

I have a question pertaining to a Client Auth rule.

Say I have a client auth rule similar to below

admins@any -> any via HTTP/HTTPS action client auth

Do any rules that have either HTTP or HTTPS in the service field have to be above the client auth rule? It appears thats the way my firewall functions but I cant find any documentation detailing this behavior. If a rule with HTTP or HTTPS in the service field is below this client auth rule it is never met. I would like to find a way around this, because this causes a number of rules to have to go above my stealth rule, which I would like to avoid if possible.
Reply With Quote
  #2 (permalink)  
Old 2007-03-15
Senior Member
 
Join Date: 2006-01-25
Posts: 920
Rep Power: 3
melipla has an average reputation (10+)
Default Re: Client Authentication rule

Quote:
Originally Posted by JPK300 View Post
Do any rules that have either HTTP or HTTPS in the service field have to be above the client auth rule?
Yes if you have the same destination this is what I have found as well, which makes sense.

Quote:
Originally Posted by JPK300 View Post
because this causes a number of rules to have to go above my stealth rule, which I would like to avoid if possible.
Can you make your rule more specific [in regards to destination]? I think that would go a long way to getting a workaround to your problem.

At the very least make a seperate client auth for your stealth rule(s) so that the real client auth rule can go below and all your other rules can stay in place.
__________________
Its all in the documentation.

Last edited by melipla; 2007-03-15 at 08:17.
Reply With Quote
  #3 (permalink)  
Old 2007-03-15
Junior Member
 
Join Date: 2007-03-13
Posts: 11
Rep Power: 0
JPK300 has an average reputation (10+)
Default Re: Client Authentication rule

Quote:
Can you make your rule more specific [in regards to destination]? I think that would go a long way to getting a workaround to your problem.
Is this in reference to the Client Auth Rule?


Quote:
At the very least make a seperate client auth for your stealth rule(s) so that the real client auth rule can go below and all your other rules can stay in place.
I dont understand what you are recommending here. I thought all Client Auth rules had to go above a Stealth rule.

Thanks for your assistance.
Reply With Quote
  #4 (permalink)  
Old 2007-03-16
Senior Member
 
Join Date: 2006-01-25
Posts: 920
Rep Power: 3
melipla has an average reputation (10+)
Default Re: Client Authentication rule

Yes I was referring to the client auth rule you posted.

I have client auth rules below my stealth rule(s).
__________________
Its all in the documentation.
Reply With Quote
  #5 (permalink)  
Old 2007-03-16
Junior Member
 
Join Date: 2007-03-13
Posts: 11
Rep Power: 0
JPK300 has an average reputation (10+)
Default Re: Client Authentication rule

I have always understood that Client Auth had to be above Stealth rules. This is what I have found in the Checkpoint documentation:

Quote:
Make sure all Client Authentication Rules are placed above the Rule that prevents
direct connections to the VPN-1 Pro Gateway (the “Stealth Rule”), so that they
have access to the VPN-1 Pro Gateway.
Do you have any other rules that allow access for client auth to be below your stealth rule?
Reply With Quote
  #6 (permalink)  
Old 2007-03-16
Senior Member
 
Join Date: 2006-01-25
Posts: 920
Rep Power: 3
melipla has an average reputation (10+)
Default Re: Client Authentication rule

In one instance I've negated http from my stealth rule, in the other I do not have it negated.
__________________
Its all in the documentation.
Reply With Quote
  #7 (permalink)  
Old 2007-03-16
Junior Member
 
Join Date: 2007-03-13
Posts: 11
Rep Power: 0
JPK300 has an average reputation (10+)
Default Re: Client Authentication rule

Thanks for the explanation.
Reply With Quote
  #8 (permalink)  
Old 2007-03-17
Senior Member
 
Join Date: 2006-04-27
Location: Twillight zone
Posts: 465
Rep Power: 3
abusharif has an average reputation (10+)
Default Re: Client Authentication rule

erm...what to you mean by cl auth rules need to be above stealth rule?

Only rules that needs to be above stealth rule is the actuall port 900 or 259 connection to the gateway. ACTUAL client auth rules don't have to be put before stealth.
Reply With Quote
  #9 (permalink)  
Old 2007-03-19
Junior Member
 
Join Date: 2007-03-13
Posts: 11
Rep Power: 0
JPK300 has an average reputation (10+)
Default Re: Client Authentication rule

I was basing the statement of where the Client Auth rule needs to be off of CheckPoints documentation. It specifically said to make sure the Client Auth was above the Stealth Rule.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 21:22.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0