CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SecureClient/SecuRemote
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-12-05
Member
 
Join Date: 2005-10-20
Posts: 47
Rep Power: 0
AndyB has an average reputation (10+)
Default SecureClient/MS AD security groups

Whilst implementing LDAP integration with NGAI R55 I have come across a problem with the firewall not reading the MS AD security groups which I have defined for my SecureClient users.

If I put the AD users in the default container 'users' I can remote in and get authenticated etc. If however, I place the user in a AD security group within the 'users' container it fails.

Everything seems to be in place, I can fetch the branch and view the securtiy group and see the user ID's in it etc. but as mentioned earlier as soon as I try and login/authenticate if fails
.
Would be grateful for any ideas.

regards
Reply With Quote
  #2 (permalink)  
Old 2005-12-07
Junior Member
 
Join Date: 2005-12-07
Location: Trois-Rivières
Posts: 27
Rep Power: 0
CheckMan has an average reputation (10+)
Default Re: SecureClient/MS AD security groups

Hi AndyB, I have the same problem with my Win2003 AD.... If you find something please let me know!!


Marc
Reply With Quote
  #3 (permalink)  
Old 2005-12-10
Member
 
Join Date: 2005-08-15
Posts: 36
Rep Power: 0
flawless_cowboy has an average reputation (10+)
Default Re: SecureClient/MS AD security groups

Did you create an LDAP group for secureclient users. By picking a specific group within an LDAP branch. I have been using AD since FP3 + win2k (management server is linux). We are now at NGX + win2k3 with no problems. Try creating a LDAP group that points directly to the CN on the group you want to authenticate from.
Reply With Quote
  #4 (permalink)  
Old 2005-12-12
Junior Member
 
Join Date: 2005-12-07
Location: Trois-Rivières
Posts: 27
Rep Power: 0
CheckMan has an average reputation (10+)
Default Re: SecureClient/MS AD security groups

No is not working... I work since 1 week directly with CheckPoint and no more result....
Reply With Quote
  #5 (permalink)  
Old 2006-01-27
Junior Member
 
Join Date: 2005-12-07
Location: Trois-Rivières
Posts: 27
Rep Power: 0
CheckMan has an average reputation (10+)
Default Re: SecureClient/MS AD security groups

Engineers and developpers of CheckPoint works on the problem since 1 month.
I will keep you up to date on this problem, this is a know problem

Marc
Reply With Quote
  #6 (permalink)  
Old 2006-01-27
Senior Member
 
Join Date: 2005-11-21
Location: Europe, Lithuania
Posts: 291
Rep Power: 4
Sergej has an average reputation (10+)
Default Re: SecureClient/MS AD security groups

Few weeks ago I'm accidentally found in CheckPoint documentation interesting thing. It is possible to map Radius users to checkpoint groups. Before I thought that radius users can only be mapped to one generic* user. This can by done via RAD_<group to which the RADIUS users belong>. This feature did not require LDAP license (this license not a problem for all-included license holders).


Quote:
Granting User Access Based on RADIUS Server Groups

With VPN-1 Pro gateway you can control access for authenticated RADIUS users, based on the RADIUS group of the user. The administrator assigns users to groups. These groups are used in the Security Rule Base to restrict or grant access for users to resources. Users are unaware of the groups to which they belong.

To use RADIUS groups, you must define a return attribute on the RADIUS Server, in the RADIUS user profile. This RADIUS attribute is returned to the VPN-1 gateway that contains the group name ( RAD_<group to which the RADIUS users belong>) to which the users belongs. By default the Class attribute is used (IETF RADIUS attribute number 25), though other RADIUS attributes can be used.

Copyright © Check Point Software
P.S. A lot of LDAP related problems fixed in HFA_01 and HFA_02
Reply With Quote
  #7 (permalink)  
Old 2006-01-27
Junior Member
 
Join Date: 2005-12-07
Location: Trois-Rivières
Posts: 27
Rep Power: 0
CheckMan has an average reputation (10+)
Default Re: SecureClient/MS AD security groups

Gotcha!!! If you a have lot of OU in your Active Directory you need to add each OU (where users is located) in the branch. Checkpoint check the credential first... After it check if the user is located in the LDAP Group (AD Group)

Marc
Reply With Quote
  #8 (permalink)  
Old 2006-06-14
Junior Member
 
Join Date: 2006-06-14
Location: AT
Posts: 20
Rep Power: 0
veste has an average reputation (10+)
Default Re: SecureClient/MS AD security groups

hello sergej,

thats exactly what i'm looking for :-)))
could you give me some hints or tell me where esactly in the documents you found this.

thx a lot,
stef

Quote:
Originally Posted by Sergej
Few weeks ago I'm accidentally found in CheckPoint documentation interesting thing. It is possible to map Radius users to checkpoint groups. Before I thought that radius users can only be mapped to one generic* user. This can by done via RAD_<group to which the RADIUS users belong>. This feature did not require LDAP license (this license not a problem for all-included license holders).

P.S. A lot of LDAP related problems fixed in HFA_01 and HFA_02
Reply With Quote
  #9 (permalink)  
Old 2006-06-14
Senior Member
 
Join Date: 2006-04-27
Location: Twillight zone
Posts: 465
Rep Power: 3
abusharif has an average reputation (10+)
Default Re: SecureClient/MS AD security groups

Quote:
Originally Posted by veste
hello sergej,

thats exactly what i'm looking for :-)))
could you give me some hints or tell me where esactly in the documents you found this.

thx a lot,
stef
sk24858 on secureknowledge containts some information about this.
Reply With Quote
  #10 (permalink)  
Old 2006-06-16
Junior Member
 
Join Date: 2006-06-14
Location: AT
Posts: 20
Rep Power: 0
veste has an average reputation (10+)
Default Re: SecureClient/MS AD security groups

Quote:
Originally Posted by abusharif
sk24858 on secureknowledge containts some information about this.
thanks!
i know i'm too stupid, but could someone please explain me, howto access
an document directly. if i change the sk# in the url, i get a blabla-page.

regards,
stef
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 15:01.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0