CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SecureClient/SecuRemote
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-07-24
topher topher is offline
Junior Member
 
Join Date: 2007-06-25
Posts: 6
Rep Power: 0
topher has an average reputation (10+)
Default VPN credential syncing-secureclient

Today a remote user’s cert expired.
I revoked the cert extended the expiration date and initiated a new cert. i saved the policy (not push) and relayed the registration key via phone to the local tech. the new cert was generated successfully, & they where able to login to HQ, but when the user tried to RDP to a remote office they received notification there login had expired.
Do i need to open the policy on each remote fw cluster and save/push the policy or will all vpn user credentials get re-synced across all fw's?
Reply With Quote
  #2 (permalink)  
Old 2007-07-24
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 1,032
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: VPN credential syncing-secureclient

To update the user database then yes need to install the security policy to all gateways to get an updated user database to them. There is a knowledgebase article that allows you to modify so that you can actually push a user database to the gateways not a whole policy install.

I am tied up at the moment or would give you a link, however there is definitely a Check Point knowledgebase article that will tell you how to do.
Reply With Quote
  #3 (permalink)  
Old 2007-07-30
topher topher is offline
Junior Member
 
Join Date: 2007-06-25
Posts: 6
Rep Power: 0
topher has an average reputation (10+)
Default Re: VPN credential syncing-secureclient

many thanks mcnallym,
i've had a look for the knowledgebase article but haven't found it. i'd really appreciate it if you could post that link.
Reply With Quote
  #4 (permalink)  
Old 2007-07-30
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 1,032
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: VPN credential syncing-secureclient

Is #sk18666


Product: VPN-1 Pro (VPN-1/FW-1)
Version: NGX, NG AI, NG
Last Modified: 29-Aug-2006







Symptoms



By default, the option to install the User Database on a Security Gateway is disabled.


Solution



To enable the option to install the User Database on a Security Gateway, proceed as follows:

Run cpstop on the SmartCenter Server.

Backup the objects_5_0.C file located in $FWDIR/conf.

Open objects_5_0.C.
Note: It is recommended that you use dbedit or GUIdbedit to modify the objects_5_0.C file.

Find :allow_install_users_db_on_module (false) and change the value "false" to "true".

Save the file.

Rename or delete any files named objects_5_0.C.bak or objects_5_0.C.backup located in $FWDIR/conf.

Run cpstart.

Now, you can install the database on Security Gateways, as well as on the SmartCenter Server.

Alternatively, you can selectively install the database without modifying objects_5_0.C by running: fwm dbload <module>.
Reply With Quote
  #5 (permalink)  
Old 2007-07-31
topher topher is offline
Junior Member
 
Join Date: 2007-06-25
Posts: 6
Rep Power: 0
topher has an average reputation (10+)
Default Re: VPN credential syncing-secureclient

thanks for the prompt reply mcnallym, your a star
Reply With Quote
  #6 (permalink)  
Old 2007-08-01
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 895
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: VPN credential syncing-secureclient

There is a second SK article that says doing this is a really bad idea. I don't know why there isn't a reference to it in that article.

If you use Install Database instead of a policy push, the database can get out of sync with the rulebase. That's why this is disabled by default and has been for the past few major releases.

Ray
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 22:16.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0