CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Web Security > SSL Network Extender
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-01-10
Junior Member
 
Join Date: 2006-10-09
Posts: 25
Rep Power: 0
res002mg has an average reputation (10+)
Default SSL NE on Vista

Hi all!
Did anyone tried SSL NE on Vista yet?
I am having problem with RDP client that comes with Vista.
I managed to make SSL NE authentication to the firewall to work, but any conection after shows up in firewall log in clear.
-ar
Reply With Quote
  #2 (permalink)  
Old 2007-07-31
Junior Member
 
Join Date: 2006-05-17
Posts: 5
Rep Power: 0
tjmadden07 has an average reputation (10+)
Default Re: SSL NE on Vista

I have been unsuccessful in getting Vista to work period. Would you mind sharing the steps taken to get SSL Network Extender to work with Vista or at least the version of firewall?
Reply With Quote
  #3 (permalink)  
Old 2007-08-01
Junior Member
 
Join Date: 2007-07-20
Posts: 2
Rep Power: 0
rgsteele has an average reputation (10+)
Default Re: SSL NE on Vista

I'm also interested in getting SSL Network Extender working on Vista. I have made some headway with getting the ActiveX control installed and getting connected, but I can't get any network traffic to travel over the encrypted link. I'll share what I've found so far.

To get the ActiveX control installed, you need to disable UAC. There's a document on SecureKnowledge here:

https://secureknowledge.checkpoint.c....do?id=sk32557

There's a couple errors in this document though. First of all, where it says

Quote:
Double-click the policy 'User Account Control: Run all administrators in Admin Approval Mode' and set it to "Enabled".
you should actually set it to "Disabled". You will also need to reboot your computer after changing these settings.

Second, these steps will only work if you are using Vista Business or Ultimate. On either of the Home versions you need to edit the registry to change these settings. I've created two .reg files for this purpose.

DisableSecurity.reg:

Code:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=dword:00000000
"EnableLUA"=dword:00000000
EnableSecurity.reg:

Code:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=dword:00000002
"EnableLUA"=dword:00000001
If anyone has managed to get traffic going over the VPN connection let us know what you did.
Reply With Quote
  #4 (permalink)  
Old 2007-08-13
Junior Member
 
Join Date: 2007-07-20
Posts: 2
Rep Power: 0
rgsteele has an average reputation (10+)
Default Re: SSL NE on Vista

The KB article has been updated. Apparently UAC can be disabled through the Control Panel. This should work on all versions of Vista.

https://secureknowledge.checkpoint.c....do?id=sk32557
Reply With Quote
  #5 (permalink)  
Old 2008-04-18
Junior Member
 
Join Date: 2005-12-11
Location: Dubai, UAE
Posts: 20
Rep Power: 0
ilmaz has an average reputation (10+)
Default Re: SSL NE on Vista

Hi

Well, I tried everything which is mentioned in the SecureKnowledge however at the end I was receiving the following message:
"Can't update the routing table! Please try again."
As a freind of mine investigated, he found that the problem is with Vista since due to built-in security, it does not allow an application to be installed and configured using a web browser. Hence, we simply downloaded the SNX client manually and installed it. Now it's working fine.

Regards,
__________________
Ilmaz S.Kashkooli (Kory)
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 17:30.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0