CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartCenter Server (Formerly Management Server)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-07-19
Junior Member
 
Join Date: 2007-06-04
Posts: 12
Rep Power: 0
FDDIcent has an average reputation (10+)
Default Enforcing password complexity for mgmt users

I'm using R55 NG AI and I was wondering if there's any easy way to enforce a password complexity scheme for Administrative users? I've poked around a bit in the GUI and CLI and do not see an option.

Thanks,
Reply With Quote
  #2 (permalink)  
Old 2007-07-19
Senior Member
 
Join Date: 2007-06-04
Posts: 1,073
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Enforcing password complexity for mgmt users

There isn't anyway that I am aware of it in SMARTDashboard. Even in R65.

For people that want more then simple password then you could hand off to a RADIUS Server and enforce a password policy in there.

A possible idea would be to make the administrators name the same as an AD username and then use IAS in Windows as a RADIUS Server. The IAS RADIUS Server then links into the AD and the AD enforces a password policy.
Saves having to create another user database.

From a Check Point perspective then just define a node for the IAS Server and then define a RADIUS Server object with the node as the Host.
On the IAS Server then define the SMARTCenter as a RADIUS Client and use the same authentication settings to link the SMARTCenter and RADIUS together.

If you don't know IAS then you will need to speak with a Microsoft expert.
Reply With Quote
  #3 (permalink)  
Old 2007-07-19
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 909
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Enforcing password complexity for mgmt users

Or use certificate authentication and make sure you have the GUI client IP restrictions in place.

Ray
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 14:39.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0