Firewall Wizards mailing list archives
Problem RADIUS FW-1 SP5/SP6 - Hybrid IKE auth
From: "Uwe Zirpner" <uz () zirpini de>
Date: Tue, 16 Jul 2002 19:10:43 +0200
Hello folks,
I do have a problem with a Checkpoint FW-1 SP6 on an solaris platform.
We need Hybrid Mode IKE urgently and I'm running out of ideas.....:-(
So far I have read the recommended papers:
- "Enabling Hybrid Mode Authentication 4.1" by Jim Parker
- "Hybrid Mode IKE for SecuRemote Authentication" from Joe DiPietro
- checked "phoneboy" site
and tried everything, which they mentioned....but it's not possible
to enable Hybrid Mode IKE on the Firewall object correctly...
Ok, here are some further details:
1: fwstop
2: get rid of objects.C.bak and objects.C.sav -- as usual
3: create internal Certificate Authority:
--> fw internalca create -dn "o=a,c=d" -force
Result: applied successfully - sounds good - no complains:-))
4: certify firewall module for SecRemote connections:
--> fw internalca certify -o fwname "o=a,c=d" -force
Result: applied successfully - sounds good - no complains:-))
5: fwstart
6: Now use the GUI and Policy Editor(BTW: same version SP6 )
In Firewall object: fwname ( BTW: external IP - in main TAB)
I checked the certificate TAB:
Result: yeah it's there - sounds good - no complains :-))
7: checked IKE Properties ind Firewall Object IKE TAB.
Result: Oooops, I cannot select Hybrid Mode ( totally grey )
That's unexpected - how come !!!!!
I tried it several times Step 1-7, still the same result!!!
I've been told, that this works easily, just read the papers,
but I'm too :$%& to enable this feature...
8: Ok, maybe you need to modify the objects.C by hand.
( ok, fwstop, get rid of object*.bak *.sav .....
add entry
:isakmp.authmethods(
:(pre-shared)
:(hybrid) ******added
)
BTW: why is it not there ???
Result: after fwstart, hoorayyy :-) I can see in the
IKE TAB of Firewall object the "Hybrid Mode" aktivated
but that is strange:
still grey and not selectable, but marked active..
9: Anyway, maybe now it works: Authentifikation of a user with
hybrid mode:
Issue a topology download, checked userc.C whether I can find
the CA lines
Result: sounds good
10: Now give it a try:
NO, it doesn't work...:-(((((
Please, I tried very short O=a ..... because FW-1 ( thank's to Dr. Leu )
has sometimes problems with long names.
But unfortunately, I cannot use shorter names ;-).
Any help, debugging hints, comments gladly appreciated..now
I'm stuck.....
TIA
Uwe
_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- Problem RADIUS FW-1 SP5/SP6 - Hybrid IKE auth Uwe Zirpner (Jul 16)
