CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SecureClient/SecuRemote
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-12-17
Artman Artman is offline
Junior Member
 
Join Date: 2006-12-06
Posts: 3
Rep Power: 0
Artman has an average reputation (10+)
Default SCV check for Windows Domain

I'm running R65 on the enforcement points and R60 for SecureClient. I'd like to use SCV to check the Windows domain of the connecting client. I'd rather not use Secure Domain Logon.

Can anyone provide help for making this check with SCV?
Reply With Quote
  #2 (permalink)  
Old 2007-12-17
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 873
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: SCV check for Windows Domain

: (RegMonitor
:type (plugin)
:parameters (
:string ("SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\DefaultDomainName=DOMAI NNAMEHERE")
:begin_admin (admin)
:send_log (alert)
:mismatchmessage ("Your computer's account is locked out. Please contact the Help Desk.")
:end (admin)
)
)


The check can be beat if someone names their computer the same as the domain. If also does not check to see if it is part of your domain, just one with the same name.

Ray
Reply With Quote
  #3 (permalink)  
Old 2007-12-18
Artman Artman is offline
Junior Member
 
Join Date: 2006-12-06
Posts: 3
Rep Power: 0
Artman has an average reputation (10+)
Default Re: SCV check for Windows Domain

Thanks for the quick reply, Ray. The only issue I see with this check is that the registry entry it checks can be changes depending on if you last logged into the local machine or (in a child domain environment) logged onto a domain that fails the check.

Is there a check for domain membership for the Windows box that is static?

Thanks for the assist!

Art
Reply With Quote
  #4 (permalink)  
Old 2008-01-03
dsb.nepo dsb.nepo is offline
Senior Member
 
Join Date: 2006-04-30
Location: Europe, Germany
Posts: 139
Rep Power: 3
dsb.nepo has an average reputation (10+)
Default Re: SCV check for Windows Domain

Unfortunately no.

for example this entry is empty at my machine
Quote:
:string ("SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winl ogon\DefaultDomainName=DOMAI NNAMEHERE")
since i use username@domain for the login.

But you can make a custom entry via DomainPolicy and query that value
Reply With Quote
  #5 (permalink)  
Old 2008-03-25
gchow gchow is offline
Junior Member
 
Join Date: 2007-11-14
Posts: 11
Rep Power: 0
gchow has an average reputation (10+)
Default Re: SCV check for Windows Domain

How can the SCV check the anti virus of the client before login in server using VPN
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 06:32.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0