Firewall Wizards mailing list archives

Problem RADIUS FW-1 SP5/SP6 - Hybrid IKE auth


From: "Uwe Zirpner" <uz () zirpini de>
Date: Tue, 16 Jul 2002 19:10:43 +0200

Hello folks,
I do have a problem with a Checkpoint FW-1 SP6 on an solaris platform.
We need Hybrid Mode IKE urgently and I'm running out of ideas.....:-(
So far I have read the recommended papers:
- "Enabling Hybrid Mode Authentication 4.1" by Jim Parker
- "Hybrid Mode IKE for SecuRemote Authentication" from Joe DiPietro
- checked "phoneboy" site
and tried everything, which they mentioned....but it's not possible
to enable Hybrid Mode IKE on the Firewall object correctly...
Ok, here are some further details:

1: fwstop
2: get rid of objects.C.bak and objects.C.sav -- as usual

3: create internal Certificate Authority:
   --> fw internalca create -dn "o=a,c=d" -force

       Result: applied successfully - sounds good - no complains:-))

4: certify firewall module for SecRemote connections:
   --> fw internalca certify -o fwname "o=a,c=d" -force
    Result: applied successfully - sounds good - no complains:-))

5: fwstart

6: Now use the GUI and Policy Editor(BTW: same version SP6 )
   In Firewall object: fwname ( BTW: external IP - in main TAB)
   I checked the certificate TAB: 
   Result: yeah it's there - sounds good - no complains :-))

7: checked IKE Properties ind Firewall Object IKE TAB.
   
   Result: Oooops, I cannot select Hybrid Mode ( totally grey )
   That's unexpected - how come !!!!!
   I tried it several times Step 1-7, still the same result!!!
   
   I've been told, that this works easily, just read the papers,
   but I'm too :$%& to enable this feature...

8: Ok, maybe you need to modify the objects.C by hand.
   ( ok, fwstop,  get rid of object*.bak *.sav .....

   add entry 
   :isakmp.authmethods(
      :(pre-shared)
      :(hybrid)   ******added
    )
    BTW: why is it not there ???
    
   Result: after fwstart, hoorayyy :-) I can see in the 
           IKE TAB of Firewall object the "Hybrid Mode" aktivated
           but that is strange: 
           still grey and not selectable, but marked active..

9: Anyway, maybe now it works: Authentifikation of a user with 
   hybrid mode:
   Issue a topology download, checked userc.C whether I can find
   the CA lines 
   Result: sounds good 

10: Now give it a try: 
    NO, it doesn't work...:-(((((

Please, I tried very short O=a ..... because FW-1 ( thank's to Dr. Leu )
has sometimes problems with long names.
But unfortunately, I cannot use shorter names ;-).

Any help, debugging hints, comments gladly appreciated..now
I'm stuck.....
TIA

Uwe  



_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: