| Platform: | any platform running Check Point VPN-1 |
| Product: | Check Point NGX and Next Generation |
| Problem: | Using Client Authentication shows the problem of user/password beeing send in cleartext. So attackers might sniff these items and start a replay attack when static passwords are used. |
| Workaround/Fix: |
Configuring SSL starts like the configuration of "normal" Client
Authentication:
The Ports for authenticating have to be accessible from the Internet, therefore the Banner should be changed as well as the ports themselves. NOTES - For using SSL first of all create a new TCP service, e.g. My1234 (port 1234/tcp). - Have a look at your Firewall object and find the nickname of the certificate
issued by the Internal Certificate Authority.
You find the nickname of this certificate under the VPN tab. - Now modify the file $FWDIR/conf/fwauthd.conf at the Firewall. It should contain a new line like the bold one:
- Then, save this file and restart the Firewall by using cpstop and cpstart.
After installing you may contact the Firewall with https to port 1234/tcp. If you use "defaultCert" as shown in the example above, you will have to accept this certificate explicitely to your browser. Then, you can authenticate as usual, but encrypted:
|
No warranty at all, your Feedback
is welcome!
© 2002-2010 AERAsec Network Services and
Security GmbH, last change 2007-01-02
back to http://www.vpn-1.de/aerasec/