CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Versions Of Firewall-1/VPN-1
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-05-16
cciesec2006 cciesec2006 is offline
Senior Member
 
Join Date: 2006-09-26
Posts: 679
Rep Power: 2
cciesec2006 has an average reputation (10+)
Default Certificate base VPN between Checkpoint firewalls

LAN_A ---CP_A -----Internet-----CP_B----LAN_B

both CP_A and CP_B is running NGx R61 with HFA_01 on Nokia IP380 IPSO 4.1
build 28.

I have VPN between LAN_A and LAN_B using preshare key and it is working
great.

I want to use Certificate based VPN instead of pre-share key. The certificate
Authority (CA) Server will be a Microsoft CA Server sitting on the Internet
with IP address of 4.2.2.2.

Anyone has the instruction on how to be able to accomplish this? Thanks.
Reply With Quote
  #2 (permalink)  
Old 2007-05-16
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 873
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Certificate base VPN between Checkpoint firewalls

Is there some reason you cannot use the built-in Check Point Internal Certificate Authority on the management server? Are these firewalls managed by the same SmartCenter or different ones?

Ray
Reply With Quote
  #3 (permalink)  
Old 2007-05-17
lammbo lammbo is offline
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 277
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: Certificate base VPN between Checkpoint firewalls

Hmmm.... maybe off-topic, but unless you are with Level3 Communications, how are you using 4.2.2.2 as your certificate server? That IP is a public DNS server.
__________________
There's no place like 127.0.0.1
Reply With Quote
  #4 (permalink)  
Old 2007-05-17
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,621
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Certificate base VPN between Checkpoint firewalls

Quote:
Originally Posted by cciesec2006 View Post
I want to use Certificate based VPN instead of pre-share key. The certificate
Authority (CA) Server will be a Microsoft CA Server sitting on the Internet
with IP address of 4.2.2.2.

Anyone has the instruction on how to be able to accomplish this? Thanks.
You will need to generate the certs and import them into the gateways (In the VPN section). You will also need to create a host for the CA and a new trusted CA under "servers". There you will import the CA's root certificate.
Reply With Quote
  #5 (permalink)  
Old 2007-05-22
cciesec2006 cciesec2006 is offline
Senior Member
 
Join Date: 2006-09-26
Posts: 679
Rep Power: 2
cciesec2006 has an average reputation (10+)
Default Re: Certificate base VPN between Checkpoint firewalls

Guys,

I was able to get it to work. In NGx R61, checkpoint allows you to use SCEP to
automatically enroll 3rd party certificate. By the way, both CP_A and CP_B
are being managed by different Provider-1 NGx. The 3rd party is a Microsoft
CA server. 4.2.2.2 is a fake IP. I wouldn't want to put my real CA Server
on the Internet so that it can get hacked right?

Now I have a different problem. I would like to make CP_A which is now a
Cicso ASA device to work with CP_B which is an NGx firewall to work in
site-2-site VPN with Microsoft CA Server. I've been trying to make
it work for almost 2 months now without much luck.

I've both Cisco and Nokia TAC involved but it is going no where. I can not make
changes in the requirements. This is what the customer wants.

Any ideas?
Reply With Quote
  #6 (permalink)  
Old 2007-05-22
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 873
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Certificate base VPN between Checkpoint firewalls

"I wouldn't want to put my real CA Server on the Internet so that it can get hacked right?"

If you have implied rules enabled, try this trick:

http://<externalIP>:18264

Ray
Reply With Quote
  #7 (permalink)  
Old 2007-05-22
cciesec2006 cciesec2006 is offline
Senior Member
 
Join Date: 2006-09-26
Posts: 679
Rep Power: 2
cciesec2006 has an average reputation (10+)
Default Re: Certificate base VPN between Checkpoint firewalls

"I wouldn't want to put my real CA Server on the Internet so that it can get hacked right?"

I mean it in the sense that the CA Server has public IP but it is not 4.2.2.2.
I just did not want to disclose it this public forum.

Both CP_A and CP_B can get the CA Server fine without issues and it works fine
and both Firewalls are Checkpoint or both firewalls are Cisco Pix but not
if CP_A is Checkpoint and CP_B is Cisco Pix.

As I've said before, both Nokia TAC and Cisco TAC are scratching their head
about this.

Will keep everyone posted.
Reply With Quote
  #8 (permalink)  
Old 2007-10-26
JohnMH JohnMH is offline
Member
 
Join Date: 2006-07-15
Posts: 68
Rep Power: 3
JohnMH has an average reputation (10+)
Default Re: Certificate base VPN between Checkpoint firewalls

I have been using an RSA certificate server for creating all my certs for use with checkpoint since 2002.

Makes a great way of making sure users are revoked...

I started using it since at that time Checkpoint did not have a way of issuing certs and needed a non user ID and password authentication for SecureClient.

John
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 07:41.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0