CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-04-04
Brittin_C Brittin_C is offline
Junior Member
 
Join Date: 2008-03-07
Posts: 26
Rep Power: 0
Brittin_C has an average reputation (10+)
Default Client Authentication to Static NAT server

Hello!

Does anyone have a sample configuration for this? I know how to set up "client auth" and how to set up "static NAT"... but how do I combine them.

The scenario is I want to use a "Client Auth" off a RADIUS KeyFoB server to grant access to a Citrix Server farm.

I have played with a couple configurations with limited success.

Thanks!
bc
Reply With Quote
  #2 (permalink)  
Old 2008-04-07
Brittin_C Brittin_C is offline
Junior Member
 
Join Date: 2008-03-07
Posts: 26
Rep Power: 0
Brittin_C has an average reputation (10+)
Default Re: Client Authentication to Static NAT server

So currently I have the following config in place:

1. NAT Rules:
Static NAT: External NAT Address of Citrix Server which is publically routed
Actual Address: internal 172.16 address which is on the interface of the Citrix Server
Service: ICMP, RDP, ICA

This rule has an opposite static rule to allow it to NAT traffic out.

2. Auth Rules
Client Auth:
User@Any ---> Citrix01Static ---> any service ---> Log

I can get a telnet login and get authorized.

If i attempt the HTTP login, it sends me to a "FireWall-1 message: ERROR: Unable to proceed. It is possible that the time out has expired. To relogin, please press this button:" Pressing the button starts the cycle all over...


Any clues what that is all about?
Reply With Quote
  #3 (permalink)  
Old 2008-04-08
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 346
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Client Authentication to Static NAT server

Check Point Authentication is aimed at local users going out. They expect you to use SecuRemote for external users coming in.

Anyway, the easiest way to configure static NAT is to use automatic (inside the object, in the NAT tab), because it will then match for both real and natted IP.
Reply With Quote
  #4 (permalink)  
Old 2008-04-10
Brittin_C Brittin_C is offline
Junior Member
 
Join Date: 2008-03-07
Posts: 26
Rep Power: 0
Brittin_C has an average reputation (10+)
Default Re: Client Authentication to Static NAT server

Only problem I am having now is the web Login give me the:
FireWall-1 message: ERROR: Unable to proceed.

After submitting the User... telnet login works fine.

Anyone know how to fix this?
Reply With Quote
  #5 (permalink)  
Old 2008-04-14
coldark coldark is offline
Member
 
Join Date: 2006-08-30
Location: Cheshire UK
Posts: 32
Rep Power: 0
coldark has an average reputation (10+)
Default Re: Client Authentication to Static NAT server

Now this may seem a little off the wall...

Which type of FW Hardware are you using? If it is Nokia, and you are using voyager on Port80 then your symptom might be because your client auth rule is below your voyager rule in the rulebase. If that's the case, switch the Client Auth rule to above the Voyager Access rule.

[Edit:] Alternatively set your voyager access to a different Port.

Last edited by coldark; 2008-04-14 at 02:57. Reason: offer an alternate situation
Reply With Quote
  #6 (permalink)  
Old 2008-04-14
Brittin_C Brittin_C is offline
Junior Member
 
Join Date: 2008-03-07
Posts: 26
Rep Power: 0
Brittin_C has an average reputation (10+)
Default Re: Client Authentication to Static NAT server

Im using a pair of Dell 2950's with dual quad port NICs on SPLAT 2.6.

Checkpoint currently has me editing the login web pages to add an "ACTION" to the "FORM" method. Whats really great is they cant tell me the exact syntax, i have to "play about and try stuff".

Im currently on "http://node1hostname.com/" next ill do "http://node1hostname:900/". The overall idea is to lock down the authenticator on one node so his login isnt interupted by the other node.
Reply With Quote
  #7 (permalink)  
Old 2008-04-14
Brittin_C Brittin_C is offline
Junior Member
 
Join Date: 2008-03-07
Posts: 26
Rep Power: 0
Brittin_C has an average reputation (10+)
Default Re: Client Authentication to Static NAT server

Happy ending...

So the solution is two fold...

First, on both clusternodes you must change the web files for login to include an ACTION in the FORM tag. This action should look like the following:

ACTION="http://<<IP or hostname of firewall node>>:900/"

This must be done on all nodes and the IP must be unique for each node. The "Real IP" of that node on the side facing the authenticator is the proper IP to insert. If your are using HTTPS for authentification then make the change accordingly to the line above.

Second, if you require the use of HTTPS to the target of your Static NAT, you must change a global property. Under global properties select SmartDashboard Customization... there should be button labeled "Configure". Click configure and navigate to: Firewall-1 --> Web Security --> HTTP Protocol. Check the box titled "http_use_host_h_as_dst". Push your policy.

If you dont check this box then Checkpoint will get all confused thinking the HTTPS is directed at it and not the NAT target and drop the packet. Why it thinks this, god only knows. If you dont need HTTPS, you can skip this step.

There ya'all go, hope it helps someone.

Last edited by Brittin_C; 2008-04-14 at 18:09.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 01:38.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0