CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDashboard
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-09-06
Junior Member
 
Join Date: 2007-02-16
Posts: 21
Rep Power: 0
ttpm123 has an average reputation (10+)
Default Adding an Administrator

Let me start by saying I'm a newbie at security and CP in particular. I have inherited several firewalls. No support contract and no training.

I am trying to add an new admin so he can use SmartDashboard. I was added as an admin by our former security admin under R55. It was upgraded to R60 prior to his moving on.

Under R55, he ran cpconfig, added me as an admin (login, pwd), added my login to /etc/ssh/securid_users, ran useradd, added my login to passwd and groups and made a directory for my login.

I did this for the new guy and then ran cpconfig and saw I cannot add an admin this way under R60 - I should use SmartDashboard. Seems straightforward but I have a question:

1. I can only use SmartDashboard myself while VPN'd with a SC static NAT. A rule allows me to connect to our VPN FW with this and then I can login to either of our management servers. If I define admin access in SmartDashboard for the new guy from 'any' do I need to also setup a static NAT for him?

I'm confused by this so I apologize if my question is a bit fuzzy.
Reply With Quote
  #2 (permalink)  
Old 2007-09-07
Senior Member
 
Join Date: 2007-04-10
Location: India
Posts: 146
Rep Power: 2
gavvys has an average reputation (10+)
Send a message via Yahoo to gavvys
Default Re: Adding an Administrator

Hi
Why you are getting so much confused.
Adding a administrator is not a big thing.
From CPCONFIG you can add only one administrator but if you want to add another admin then you have to add that in SmartDashboard.Just right click on administrator and click new and you can give him read/write rights also.

I hope this will help you.
If you have any query let me know.
Regards
Ranjit
Reply With Quote
  #3 (permalink)  
Old 2007-09-07
Junior Member
 
Join Date: 2007-02-16
Posts: 21
Rep Power: 0
ttpm123 has an average reputation (10+)
Default Re: Adding an Administrator

OK, beneath 'Administrator' is an object 'cpconfig_administrators'. In 'cpconfig_administrators' are myself and boss (who has been out of STD for months). When I right-click 'Administrator' and choose New Administrator, add name and permissions and go to the next tab, a pop-up says 'name already used'. This is the name of the 3rd admin I WANT to add. Where would he be defined elsewhere? He does not have admin priv - login fails.

I am assuming it's from the files I added him to under the mistaken R55 process. But it is odd that the FW would read those files, see his credentials and not allow access. Seems it should not recognize the additional entry at all.
Reply With Quote
  #4 (permalink)  
Old 2007-09-07
Senior Member
 
Join Date: 2007-07-16
Posts: 603
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: Adding an Administrator

There's probably a legacy cpconfig administrator from before you performed your upgrade. Run cpconfig from command prompt and list the administrators there. Delete all that are not required, and re-create them in the Dashboard.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 13:59.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0