CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-02-03
Huisje Huisje is offline
Junior Member
 
Join Date: 2005-11-10
Posts: 17
Rep Power: 0
Huisje has an average reputation (10+)
Default Access management station from the entire LAN

Hello,

I would like to set up a way so I can access the management station via the SmartConsole tools from the entire LAN and not just from the IP's I have configured as GUI clients with cpconfig. I do not want to add the ranges of all the LANs here to the GUI clients' IP list though. I was wondering if there was some way I could "bounce" the connection over another host. I have a network monitoring host running linux/debian and ideally I would connect with smartconsole to that device which would relay it to the CP Firewall.

Does anybody have any ideas or tips on how to achieve this? Or maybe a tutorial somewhere?

Thanks.

Kevin
Reply With Quote
  #2 (permalink)  
Old 2006-02-04
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,637
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Access management station from the entire LAN

port forwarding using SSH will work Port 18190 will get you the policy editor (smartdashboard). Don't know which others you need off hand.
Reply With Quote
  #3 (permalink)  
Old 2006-02-05
Huisje Huisje is offline
Junior Member
 
Join Date: 2005-11-10
Posts: 17
Rep Power: 0
Huisje has an average reputation (10+)
Default Re: Access management station from the entire LAN

Thanks Jim.

How do I go about with this? The Dashboard login screen doesn't have an option to enter a place to bounce using ssh, so I assume I will need to set this up on my management host, the one I want to bounce on.

How will it handle the SSH authentication though? I can set up a port forward easy enough, but a bounce is something different all together. I want it to require authentication for the SSH connection and of course it needs to actually change the source address of my traffic because otherwise the CP will not allow it.

Any tips?

kind regards,

Kevin
Reply With Quote
  #4 (permalink)  
Old 2006-02-05
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,637
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Access management station from the entire LAN

There is a good detailed artical at http://www.securityfocus.com/infocus/1816

But the shourt version is you need a ssh client on the system you are using and an ssh server that can access the firewall

Personally I use an internal linux system as the ssh server and VanDyke's etunnel as my client.
Reply With Quote
  #5 (permalink)  
Old 2006-02-05
Huisje Huisje is offline
Junior Member
 
Join Date: 2005-11-10
Posts: 17
Rep Power: 0
Huisje has an average reputation (10+)
Default Re: Access management station from the entire LAN

Thanks again. That article is very clear.

The piece of software you suggest (which I think is called Entunnel, not Etunnel) is not freeware.
I first tested this with "SSH Tunnel Client 3.0" which is free for personal use. Available on many download sites, publisher's page seems to be: http://www.delight.ch/ (but it's in German). This works just as you described.

I then snooped arround some more and found out you can also achieve this with Putty. It is simple and I used this guide to set it up: http://www.cs.uu.nl/technical/servic...y/puttyfw.html

And to the best of my knowledge I can use this for professional use for free.

My management host is a linux machine and already has an sshd running. Tomorrow at work I will test this "for real" since at the moment that host is not allowed as a GUI client on the firewall. I tested this at home with a tunnel to some other application and it works fine, so I'm confident it'll turn out ok tomorrow too.

regards,

Kevin
Reply With Quote
  #6 (permalink)  
Old 2006-02-06
Huisje Huisje is offline
Junior Member
 
Join Date: 2005-11-10
Posts: 17
Rep Power: 0
Huisje has an average reputation (10+)
Default Re: Access management station from the entire LAN

Well, this works very efficiently. I have set up Putty to tunnel both CPMI (TCP 18190) and SSH (TCP 22) over my linux management host. Over that tunnel I can access the CP over the GUI from anywhere on the LAN (read: from any network range from which I am able to set up the tunnel to the management host).

Thanks for the help.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 14:15.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0