CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDashboard
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-06-15
Scrif Scrif is offline
Junior Member
 
Join Date: 2007-06-14
Posts: 26
Rep Power: 0
Scrif has an average reputation (10+)
Default Deleting users in SmartDashboard

Im kinda new to the checkpoint world and just need some clarification.

We run SmartDashboard and connect to our firewall managers. From there I can load the different policies for our Nokia Firewalls. I need to delete a couple of users. The users belong to a particular group, and the group is used in a rule in a particular policy. However, it doesn't matter which policy I have open, I can still see all the user object available. So to me, the user database is independent of the policies (so to speak)

My question is, can I just delete the user from the database? Do I need to verify/push the policy for the firewall that these users have access to (by virtue of their group)?

Thanks
Reply With Quote
  #2 (permalink)  
Old 2007-06-15
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,632
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Deleting users in SmartDashboard

You may just delete the users from the manage->users section of smartdashboard, save and install database. I would push policy just to be safe.
Reply With Quote
  #3 (permalink)  
Old 2007-06-16
Scrif Scrif is offline
Junior Member
 
Join Date: 2007-06-14
Posts: 26
Rep Power: 0
Scrif has an average reputation (10+)
Default Re: Deleting users in SmartDashboard

Thanks for the reply.

What does 'install database' actually do? Maybe I dont fully understand how the user database is ued. Is it a local database on the Firewall Manager?

And is the only policy I need to push the one which uses the group to which the deleted users belong(ed)?

Thanks again.
Reply With Quote
  #4 (permalink)  
Old 2007-06-16
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 873
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Deleting users in SmartDashboard

You should always consider pushing the policy after deleting users as there were issues in earlier versions (propr to R60 HFA04).

If the user database is used in a rule, doing the Install Database thing can cause an inconsistency between the database and the security policy. sk31889 gives an example of Office Mode failing because of Install Database.

I would think you would be safe in just pushing the policy where the users are used.

Ray
Reply With Quote
  #5 (permalink)  
Old 2007-06-16
Scrif Scrif is offline
Junior Member
 
Join Date: 2007-06-14
Posts: 26
Rep Power: 0
Scrif has an average reputation (10+)
Default Re: Deleting users in SmartDashboard

So you're saying do NOT do an Install Database? Just delete the users, and push the policy for the firewall which contains the group the users were in?

Thanks.
Reply With Quote
  #6 (permalink)  
Old 2007-06-16
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 873
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Deleting users in SmartDashboard

Yes, that will work fine. I never use Install Database.

Oh, and if you remove them from any group that they were created with and later try to delete them, you will get this message about an error and them not being deleted. Just add them back into their group and then delete them.

Ray
Reply With Quote
  #7 (permalink)  
Old 2007-06-18
Scrif Scrif is offline
Junior Member
 
Join Date: 2007-06-14
Posts: 26
Rep Power: 0
Scrif has an average reputation (10+)
Default Re: Deleting users in SmartDashboard

Actually, I have one more question - the reverse now. If I create a user using Dashboard and give them Admin-RW, do they also get a shell (command line) account automatically? Or do I need to create a shell account for them as well?

If I do, what are the command to create the account?

Thanks again for all your help.
Reply With Quote
  #8 (permalink)  
Old 2007-06-18
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 873
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Deleting users in SmartDashboard

The SmartCenter account has nothing to do with access to the underlying operating system. What OS is the SmartCenter running on?

Ray
Reply With Quote
  #9 (permalink)  
Old 2007-06-18
Scrif Scrif is offline
Junior Member
 
Join Date: 2007-06-14
Posts: 26
Rep Power: 0
Scrif has an average reputation (10+)
Default Re: Deleting users in SmartDashboard

I did a uname -o and it came back with GNU/Linux
Reply With Quote
  #10 (permalink)  
Old 2007-06-18
RobertGraham RobertGraham is offline
Senior Member
 
Join Date: 2006-02-02
Posts: 204
Rep Power: 3
RobertGraham has an average reputation (10+)
Send a message via MSN to RobertGraham Send a message via Yahoo to RobertGraham
Default Re: Deleting users in SmartDashboard

You'll need to add a normal OS level Linux user as if the SmartCenter never existed. Things you do in SmartCenter have nothing to do with the Linux OS. As such, it can't anything from SmartCenter as far as the users go.

BTW: In Linux this is usually done with the adduser command.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 03:14.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0