CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-01-25
pemuller pemuller is offline
Junior Member
 
Join Date: 2007-11-22
Posts: 10
Rep Power: 0
pemuller has an average reputation (10+)
Default Generate mail alert for "illegal" access

I currently have a rule in my SmartCenter specifying that a certain User Group is allowed SecuRemote access to a certain number of hosts using a certain set of protocols.

I would like to set up a mail alert to be generated if a user tries to access other hosts than those allowed or if a user tries to use a protocol other than those allowed. How can I do this?
Reply With Quote
  #2 (permalink)  
Old 2008-01-27
dsb.nepo dsb.nepo is offline
Senior Member
 
Join Date: 2006-04-30
Location: Europe, Germany
Posts: 131
Rep Power: 3
dsb.nepo has an average reputation (10+)
Default Re: Generate mail alert for "illegal" access

It is possible if you crate a group for all SecuRemote users, them move all the Remote access rules at the top of the rulebase.
Create the a cleanup rule for the Remote access after the Remote access permit rules

for example:
Code:
source       | destination |     VPN     | service | action | track 
-------------|-------------|-------------|---------|------------------
SR-Users@any | SRV-GRP1    |RemoteAccess | http    | accept | log
SR-Users@any |   any       |RemoteAccess | any     | reject | mail
Before implementing this take a look at your logfiles, look at the VPN log section with a filter like this
'column USER not empty' to get an impression how many mails you will find in your mailbox.
Reply With Quote
  #3 (permalink)  
Old 2008-01-31
pemuller pemuller is offline
Junior Member
 
Join Date: 2007-11-22
Posts: 10
Rep Power: 0
pemuller has an average reputation (10+)
Default Re: Generate mail alert for "illegal" access

I had thought of this, but I end up getting the error message:
Action can be only Accept when the "VPN" includes SR Community Objects
when I verify the policy.
Reply With Quote
  #4 (permalink)  
Old 2008-01-31
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 346
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Generate mail alert for "illegal" access

Interesting, please do keep us posted on results, sadly I don't "own" any Check Point now, so I can't really check or advise on this (since demo mode doesn't allow me to "Verify Policies").

One thing that will happen if you get this working is that you will get loads of emails. There will be broadcasts, mistakes, etc...
Reply With Quote
  #5 (permalink)  
Old 2008-02-01
dsb.nepo dsb.nepo is offline
Senior Member
 
Join Date: 2006-04-30
Location: Europe, Germany
Posts: 131
Rep Power: 3
dsb.nepo has an average reputation (10+)
Default Re: Generate mail alert for "illegal" access

If you only accept office mode you can use the assigned network for a alert rule.

Lets say you have assigned 192.168.10.0/24 as the office mode pool you can make a rule like the following.

Code:
source            | destination |     VPN     | service | action | track 
------------------|-------------|-------------|---------|------------------
SR-Users@any      | SRV-GRP1    |RemoteAccess | http    | accept | log
Net_192.168.10-24 |   any       |RemoteAccess | any     | reject | mail
Reply With Quote
  #6 (permalink)  
Old 2008-02-03
pemuller pemuller is offline
Junior Member
 
Join Date: 2007-11-22
Posts: 10
Rep Power: 0
pemuller has an average reputation (10+)
Default Re: Generate mail alert for "illegal" access

Good thinking. I may be able to do something with this idea. I currently however have several different groups of SecuRemote users, some allowed access to the specific servers and other "groups" not. They all use the same Office Mode addresses. I need to think a bit more about this.
Reply With Quote
  #7 (permalink)  
Old 2008-02-05
dsb.nepo dsb.nepo is offline
Senior Member
 
Join Date: 2006-04-30
Location: Europe, Germany
Posts: 131
Rep Power: 3
dsb.nepo has an average reputation (10+)
Default Re: Generate mail alert for "illegal" access

There is a way you can control the ipaddress of your users.
- with radius, i have done this with IAS (use this only if the radius is exclusive for CP and not also for other network devices)
- ipassignment.conf (needs sometimes a restart of cp so not prefered)
- '$> vpn macutil username' and reserved IP at the dhcp server for OfficeMode (i use this at the moment)

That gives me also the whish to have a simple tool at the GUI station to generate the virtual MAC, if you use splat you can do this at the moment only on the MGMT/FW modul as expert.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 13:20.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0