CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SecureClient/SecuRemote
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-04-24
ppawlo ppawlo is offline
Member
 
Join Date: 2007-02-17
Posts: 42
Rep Power: 0
ppawlo has an average reputation (10+)
Default Remote connection by AD certificates - What do you think about it?

Hym, from few years we have been using remotely connection. We create certificate on our FW. Next we import this certificate to user and set the password to this. People to connection need the CP certificate.
I think it is very good solution, very secure.
Now, we need to reinstall SmartCenter. Unfortunately after that we will have lost all certificates. Now we have got about 80 users with certificates. So, before we reinstall SmartCenter we need change the authentication of connection. By the way we have only three choice:

Authentication by checkpoint’s password
Authentication by user password of Active Directory
Authentication by user certificate of Active Directory.

Ad 1. I think it is very unsecure. Checkpoint password has only 8 letters.
Ad 2. I think it also unsecure. When I know login name and password of my colleague I will be able not only to their computers but also to their other sites.
Ad 3. I think it is a good solution. I heard a lot about it and everything looks great. What do you think about this solution? Do you know some weaknesses of it?

Will our user be able to revoke their certificate remotely or automatically without administrator?
Are we able to set using the password (strong private key protection).

Thank you for help,
Pawel
Reply With Quote
  #2 (permalink)  
Old 2008-04-27
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,598
Rep Power: 4
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Remote connection by AD certificates - What do you think about it?

I've never done it myself, but if implemented well it should work as well if not better than ICA certs.

Personally I never found the idea of having, as part of a two-factor authentication, the 2nd factor (the Cert) on the same laptop as the VPN client, especially as most people set the cert password to something simple.

I prefer something like SecureID or certs stored on SmartCards (Or the USB-key like smartcard).

Now the real question is whey do you need to reinstall the SmartCenter and disttroy the ICA?
Reply With Quote
  #3 (permalink)  
Old 2008-05-01
ppawlo ppawlo is offline
Member
 
Join Date: 2007-02-17
Posts: 42
Rep Power: 0
ppawlo has an average reputation (10+)
Default Re: Remote connection by AD certificates - What do you think about it?

Quote:
Originally Posted by chillyjim View Post
I've never done it myself, but if implemented well it should work as well if not better than ICA certs.

Personally I never found the idea of having, as part of a two-factor authentication, the 2nd factor (the Cert) on the same laptop as the VPN client, especially as most people set the cert password to something simple.

I prefer something like SecureID or certs stored on SmartCards (Or the USB-key like smartcard).

Now the real question is whey do you need to reinstall the SmartCenter and disttroy the ICA?
Hi
When we talk about SmartCenter, unfortunately from few years old administrator has done only upgrade. A check the filesystem and there is R55 also (now we have NGX R65). At the moment we have a lot of troubles (we could not innstal the policy, we could not login correctly to SC) so we could not do upgrade_export. We have to use command like cp_merge .


Regards
Pawel
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 13:46.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0