CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SecureClient/SecuRemote
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-05-02
RobertGraham RobertGraham is offline
Senior Member
 
Join Date: 2006-02-02
Posts: 204
Rep Power: 3
RobertGraham has an average reputation (10+)
Send a message via MSN to RobertGraham Send a message via Yahoo to RobertGraham
Default How do I prevent a desktop policy from being downloaded/enforced?

In my case, I had a test client that I didn't want to downloading the policy and start blocking stuff. It should run the SecureClient software, connect to the gateway, but not download or install the desktop policy.

There are a couple ways to do this, but the simplest route I found:
  1. Delete all the files in the policy folder
  2. Set the permissions to read/exec only on the policy folder.
  3. Restart the client

Caveat: This doesn't scale particularly well. You might be able to write this into group policy if you wanted to, but that's probably not necessary very often anyway.

PS: I tried manipulating the policy files and setting them to read-only, but the client whined or ignored it and I gave up on that. If you have done this before, I'd be really happy to read your post.
Reply With Quote
  #2 (permalink)  
Old 2007-05-03
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,632
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: How do I prevent a desktop policy from being downloaded/enforced?

On the policy server object, go to authentication->policy server and chose a group for users to receive a policy and put your test user/client in a different RA group
Reply With Quote
  #3 (permalink)  
Old 2007-05-03
RobertGraham RobertGraham is offline
Senior Member
 
Join Date: 2006-02-02
Posts: 204
Rep Power: 3
RobertGraham has an average reputation (10+)
Send a message via MSN to RobertGraham Send a message via Yahoo to RobertGraham
Default Re: How do I prevent a desktop policy from being downloaded/enforced?

Jim:

Sorry I didn't specify, but this test user is used in several different testing scenarios. So, I can't change anything on the "server" side lest the other things break.

Under these circumstances, any changes would have to take place on the client side.

Robert
Reply With Quote
  #4 (permalink)  
Old 2007-05-03
melipla melipla is offline
Senior Member
 
Join Date: 2006-01-25
Posts: 788
Rep Power: 3
melipla has an average reputation (10+)
Default Re: How do I prevent a desktop policy from being downloaded/enforced?

Quote:
Originally Posted by chillyjim View Post
On the policy server object, go to authentication->policy server and chose a group for users to receive a policy and put your test user/client in a different RA group
Is that an R60 option?
Reply With Quote
  #5 (permalink)  
Old 2007-05-03
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,632
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: How do I prevent a desktop policy from being downloaded/enforced?

Quote:
Originally Posted by melipla View Post
Is that an R60 option?
Yeah I think it started with NGX when the policy server was included with the VPN-1 license.
Reply With Quote
  #6 (permalink)  
Old 2007-05-03
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,632
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: How do I prevent a desktop policy from being downloaded/enforced?

Quote:
Originally Posted by RobertGraham View Post
Jim:

Sorry I didn't specify, but this test user is used in several different testing scenarios. So, I can't change anything on the "server" side lest the other things break.

Under these circumstances, any changes would have to take place on the client side.

Robert
In that case, you lose. The whole point of SVC is it isn't end user modifiable.
Reply With Quote
  #7 (permalink)  
Old 2007-05-07
RobertGraham RobertGraham is offline
Senior Member
 
Join Date: 2006-02-02
Posts: 204
Rep Power: 3
RobertGraham has an average reputation (10+)
Send a message via MSN to RobertGraham Send a message via Yahoo to RobertGraham
Default Re: How do I prevent a desktop policy from being downloaded/enforced?

You mean, you lose unless you do it the way I described in my original post. ;-)

Another option would be to write a script that runs after the policy download and overwrites the policy downloaded with one that contains nothing. But, that hardly seems like it's worth the effort.
Reply With Quote
  #8 (permalink)  
Old 2007-06-12
RobertGraham RobertGraham is offline
Senior Member
 
Join Date: 2006-02-02
Posts: 204
Rep Power: 3
RobertGraham has an average reputation (10+)
Send a message via MSN to RobertGraham Send a message via Yahoo to RobertGraham
Default Re: How do I prevent a desktop policy from being downloaded/enforced?

In the end I ended up simply unbinding SecuRemote from the NIC. That worked great!


...until they upgraded the gateway from NG to NGX and the whole thing blew up.

Now I'm back to figuring out how to disable the policy or preventing the policy from ever being loaded. :-(
Reply With Quote
  #9 (permalink)  
Old 2007-06-14
melipla melipla is offline
Senior Member
 
Join Date: 2006-01-25
Posts: 788
Rep Power: 3
melipla has an average reputation (10+)
Default Re: How do I prevent a desktop policy from being downloaded/enforced?

Good to see that SCV actually works..in NGX at least :) Let me know if figure out a way around it!
Reply With Quote
  #10 (permalink)  
Old 2007-06-14
RobertGraham RobertGraham is offline
Senior Member
 
Join Date: 2006-02-02
Posts: 204
Rep Power: 3
RobertGraham has an average reputation (10+)
Send a message via MSN to RobertGraham Send a message via Yahoo to RobertGraham
Default Re: How do I prevent a desktop policy from being downloaded/enforced?

OK, this is completely nuts! With all the difficulties of making sure that we block the policy download with SecureClient, we finally decided to move to SecuRemote. We're only trying to test the authentication anyway...

So, I uninstalled SecureClient, downloaded the latest and greatest installer (R60HFA02) and proceeded to install SecuRemote. Policy problem - gone. However, this tunnel_test nonsense began to rear its ugly head once again.

Two sites were configured, and for the one it always did a tunnel test. I found it strange that it was the first site created after the fresh installation. Sooooo....I deleted the site and recreated it and VOILA! It works.

There's no real solid info on the tunnel test application in the SecureKnowledge and several of my questions remain unanswered. I don't have the luxury of doing the research now. But eventually I will...
Reply With Quote
  #11 (permalink)  
Old 2007-08-03
jrdld jrdld is offline
Junior Member
 
Join Date: 2005-11-11
Posts: 23
Rep Power: 0
jrdld has an average reputation (10+)
Default Re: How do I prevent a desktop policy from being downloaded/enforced?

In R56 you can do this by excluding the user from the group of users allowed to use the policy server. In the firewall object, goto Authentication, and look in the Policy Server section. There will be a group of users selected there. If you can isolate the user from that group, they won't get policy updates. I found this to my cost when a couple of new users weren't getting policy updates, because they were in a newly configured group, which had not been added to the group given access to the policy server.

JR
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 01:58.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0