Re: Authentication with Firewall-1 NG with AI

From: Dan (bitsandbytes88_at_hotmail.com)
Date: 01/28/04


Date: Wed, 28 Jan 2004 17:32:05 -0500

Does anyone no when checkpoint expects to provide client authentication for
ssh as well as telnet, ftp, http and https, and rlogin?

Thanks.

"Jason Kau" <jkau@vulture.cnd.gatech.edu> wrote in message
news:bv331f$jap$1@news-int2.gatech.edu...
> MichaelK <m_keightley@yahoo.co.uk> wrote:
> > Seems that S/Key authentication has been removed from the latest version
> > of Firewall-1 (NG with Application Intelligence R55).
> > We have lots of Linux and MacOSX users, SecuRemote only seems to be
available
> > for Window$.
>
> SecuRemote NG is available for Redhat 7.2 and 7.3--not sure if it will
work
> with later versions of RedHat. You should be able to get FreeS/WAN to
work
> with VPN-1. As for MacOS X, you can use third-party VPN clients like
> VaporSec or Equinux VPN Tracker.
>
> > Found SecuRemote to be very flakey software on Windows anyway.
>
> SecuRemote NG FP3 Build 53515 has worked great for us on Win2K/XP.
>
> > So how are people meant to authenticate securely.
>
> RSA SecurID or any other time-synchronization tokens that can be accessed
via
> RADIUS/TACACS, e.g. Vasco? Client certificates (Entrust or internal CA)?
>
> --
> Jason Kau
> http://www.cnd.gatech.edu/~jkau