CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDashboard
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-05-16
Anita Anita is offline
Junior Member
 
Join Date: 2006-04-27
Posts: 12
Rep Power: 0
Anita has an average reputation (10+)
Default Timeout configuration

Dear all,

Is it possible to configure timeout for the administrator logged in to the dashboard in R55.
If yes, could anyone tell me how to configure it.

Thanks in advance.....
Reply With Quote
  #2 (permalink)  
Old 2008-05-14
kraskov kraskov is offline
Junior Member
 
Join Date: 2008-01-25
Posts: 2
Rep Power: 0
kraskov has an average reputation (10+)
Default Re: Timeout configuration

Hi
I have interested too but for R65...
Reply With Quote
  #3 (permalink)  
Old 2008-05-14
dantro dantro is offline
Senior Member
 
Join Date: 2007-02-07
Location: Halle (Saale)
Posts: 200
Rep Power: 2
dantro has an average reputation (10+)
Default Re: Timeout configuration

Imagine you just edited twenty rules and you pick up an incoming phone call which is longer than your session timeout. You would be logged out and all changes would be lost. Or even worse, you deleted a object which had a VPN certificate installed, the certificate got deleted and the session timeout logs you out. The deleted object would still be there after your next login while the VPN certificate would not. Check Point knew that a session timeout could lead to reference errors in the objects database due to unsaved states while logging someout out this way. Also a lot of other unwanted side-affects could appear. In an IT-security environment you want stable processes and states.

Better create readonly and readwrite admin profiles and use these instead of looking for a session timeout to log someone out that is logged in for hours or days by a session timeout. Multiple admins may be logged in at the same time in readonly mode to check SmartView Monitor or SmartView Tracker for a longer time period. If someone needs to edit the security policy or something, he might log in with readwrite permission and logout afterwards.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 01:47.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0