Wednesday, February 9, 2011

What is EndPoint Connect

Check Point`s Endpoint Connect software provides a number of client side security based features such as Anti-virus/Anti-spyware. Firewall/Email Protection, Program Control and Remote Access VPN. This document will only details and discuss the Remote Access VPN section of the Endpoint Connect Software. Note : This document will refer to the Endpoint Connect Remote Access VPN as just Endpoint Connect.
Endpoint Connect is built into the software for mangers and gateways running R70 and above. For R65 gateways that require Endpoint Connect a few additional configuration steps are required which are included within this document.
Please note : This testing and documentation is based on the Endpoint Connect R73 Client.
Advantages
  • Lightweight Client if you are using a single site or single entry point setup.
  • Can be installed onto Windows 7 64-bit.
Disadvantages
  • An additional SNX (SSL Network Extender License) is required due to that in which it authenticates across HTTPS (vistor mode)
  • Link Selection is disabled (this is due to sites being defined via a single IP address).
  • MEP configurations can only be achieved by using Geo-Cluster DNS name resolution.
Installation on an R65 Gateway
Upgrading a R65 Gateway to R65 Endpoint Connect:
  1. Ensure that you are running HFA40 or higher.
  2. Ensure that you are managing the gateway with R70 or higher.
You will now be able to configure the required Endpoint Connect settings via the Smart Dashboard.
Configuration
To enable Endpoint Connect configure/enable the following settings :
Under the Check Point Gateway Object
1. Enable VPN

2. Create a VPN domain



3. Enable NAT-T


4. Enable Visitor Mode :

5. Enable Office mode



6. Enable SSL Network Extender



7. Endpoint connect doesn`t support DES. If this is set please re-configure.


Additional Settings
Further settings can be set within the Global Properties:


Troubleshooting
Issue : Authenticating failed: GEN_application_error(0)
You may receive this error when trying to login.


This is down to your client being unable to authenticate with the VPN gateway using HTTPS. This can be caused by the following:
            1.      Port 443/tcp on the firewall is assigned to a web management GUI (WEBUI/Voyuger) instead of VPND.
            2.      Port 443/tcp is not listening due to no SNX (SSL Network Extender) License being present.
Issue : Failed to download topology
Endpoint Connect fails to connect to NGX R65 Security Gateways that are managed by an R70 Security Management server with error: "failed to download topology".
To resolve this run through the following steps :
          1.      On the R70 Security Management server, edit the file:
1./opt/CPNGXCMP-R70/lib/vpn_table.def
         2.      Scroll down to the section that starts with:
1./* Slim Client gateway tables */
         3.      Add the entry for the ccc_sessions table below it:
1.ccc_sessions            = dynamic expires 900 keep sync kbuf 1;
         4.      After adding this entry to the vpn_table.def file, open SmartDashboard and re-install policy to the NGX R65 Security Gateway(s).

Tuesday, February 8, 2011

How to troubleshoot SSHd problems

1. Is sshd wrapped with tcp-wrappers? Assuming the sshd daemon is invoked from inetd, your /etc/hosts.allow should list acceptable addresses from which connections are allowed.

2. Is sshd running on the standard port 22 or another? If running on a non-standard
port, make sure that your ssh client is specifying the target port.

3. Which sshd version is running? There are many problems with sshd2 used in
conjunction with tcp-wrappers. sshd1 runs with fewer difficulties wrapped. Also, the
ssh1 client has difficulty connecting to a sshd2 server.

4. Make sure that your /etc/services reflects the ssh service on the designated
port! /etc/services and tcp-wrappers work together when invoking the sshd daemon.

Example: sshd1 running on port 700 should have an entry in /etc/services as such:

ssh1        700/tcp    #ssh1
ssh1        700/udp

While in inetd.conf, the invoking line should read:

ssh1    stream  tcp     nowait  root    /usr/sbin/tcpd /usr/local/sbin/sshd1 -i -p 700

Monday, February 7, 2011

How to perform a clean installation of firewall-1 on a Nokia Platform

   1) In the Voyager interface, use the Manage Installed Packages to turn off the package, then reboot
    2)In the Voyager interface, on the Manage Installed Packages page, there is a link to a page to delete packages. Follow this link and delete the package
    3)Use a console connection to delete any remaining log files. For example, FireWall-1 maintains its logs in the /var/fw/log directory. Simply issue an
    # rm /var/fw/log/*
    4)command to remove all log files.
    Use the "newpkg" command to reinstall the package.

 

Sunday, February 6, 2011

How to switch logs on a Nokia system

Here below is an example of log rotation for IPSO

#!/bin/sh
#
# Set environment variables
sh /var/etc/rcm_profile
#
cd /var/fw/log
#
# Switch CheckPoint log into dated file for saving
# Surpress resolving of IP/names
PERIOD=`date "+%d%m%y"`
$FWDIR/bin/fw logswitch $PERIOD 2> /dev/null
#
# output logfile to comma seperated variable file
$FWDIR/bin/fw logexport -d , -i $PERIOD.log -o yesterday -n 2> /dev/null
#
# search for all dropped packets
ATTACK=$PERIOD.attack
grep "drop" yesterday >> $ATTACK
#
# uuencoded files will be interpreted as an attachment by most mail clients
uuencode $ATTACK $PERIOD.csv > $PERIOD.csv
#
# mail attack to system administrator
mail -s "Fire Log Switch" fwadmin@corp.com < $PERIOD.csv

Saturday, February 5, 2011

How to perform a local simulation for a remote module in order to configure it before shipment

Simulation is usefull when you are preparing equipments for remote locations. From the management module you can prepare the policy. But then you will need to download it on the remote module. If you can simulate the remote network locally you will find it easier to prepare and troubleshoot configurations.

External interface is ethernet and will be connected to a router

For the simulation you will need to change the configuration of your Internet router. You will assign a secondary interface to the router's ethernet interface. This address is the one of the remote site Internet router.

!
interface Ethernet0
ip address 192.168.10.253 255.255.255.0 secondary
ip address 194.191.78.36 255.255.255.224

By extending the number of secondary addresses you can simulate several remote locations at the same time.

External interface is on serial Interface

You will need to simulate the serial connection locally. That kind of serial connection can be of type Cisco HDLC, Frame Relay or PPP. For the simulation you will need to use a local cisco router with an available serial port

If your external interface is serial 0 on a cisco router, you will configure it in DCE mode. For this use Cisco DCE cable. The fact to have a DCE cable put the cisco serial interface in a DCE mode. Then configure the serial interface to give a clock rate to the connection. The NAP cannot work in a DCE mode itself. The nokia V.35/X.21 cable will be connected to the cisco DCE cable, and bothe connected to their respectiv serial ports. The IP address given to the serial interface of the router is the one of the remote site Internet router.


!
interface Serial0
ip address 194.193.192.254 255.255.255.252
clockrate 64000

Friday, February 4, 2011

How to SYNC on Solaris 2.6/cluster patches and FW1-v3.0b 3064 patch

I want to pass on some info about SYNC on Solaris 2.6/cluster patches
and FW1-v3.0b 3064 patch. This is undocumented but a must!

This seems to be crucial on systems where the control module and pfm
are not on the same system...

Our config has three systems. Non-vpn and no NAT just packet
filtering...

control
pfm
pfm

Creating /etc/fw/sync.conf and putkey on the pfm modules is not enough!

Modify the file below table.def and comment out the "#define sync"
command.
Then recompile and download your rule sets to the pfm modules...

This seems to be crucial on systems where the control module and pfm
are not on the same system...so if you have two systems

control/pfm
pfm

you will need to do this table.def mod...

$ more /etc/fw/lib/table.def
#ifndef __table_def__
#define __table_def__

//
// (c) Copyright 1993-1997 Check Point Software Technologies Ltd.
// All rights reserved.
//
// This is proprietary information of Check Point Software Technologies
// Ltd., which is provided for informational purposes only and for use
// solely in conjunction with the authorized use of Check Point Software
// Technologies Ltd. products. The viewing and use of this information
is
// subject, to the extent appropriate, to the terms and conditions of
the
// license agreement that authorizes the use of the relevant product.
//
//
// $Header: /fw/cvs/fw-1/fwlib/table.def,v 1.42.2.20 1998/01/01 08:09:47
ofer Ex
p $
//

// The following #define should be removed to enable FW-1
synchronization
//#define sync

Thursday, February 3, 2011

What should I be aware of when upgrading from version 4.0 to 2000

When upgrading from Version 4.0 to Check Point 2000, the Management Station checkbox in the Workstation Properties window will be checked only for the Management Station being upgraded. All other gateways defined on the Management Station will have the Management Station checkbox unchecked by default.

When you upgrade, the $FWDIR/lib/control.map file is replaced. If you have made any changes
to control.map, they will not be preserved in the new control.map, so you must make the same changes in the new version.



Session Authentication Agent — Installing the Version Check Point 2000 Session Authentication Agent does not overwrite the Version 4.0 Session Authentication Agent. You must uninstall the Version 4.0 Session Authentication Agent (using the Control Panel’s Add/Remove Programs applet) and then install the Version Check Point 2000 Session Authentication Agent. Note that the Session Authentication Agent is shut down as part of the uninstallation process, so you must manually restart it (or reboot).



VPN-1/FireWall-1 HP Open View Extension supports Solaris and HP-UX with HP OV version 4.x. HP-UX with HP OV versions 5.x and 6.x is not supported.

 Synchronized VPN/FireWall Modules —

    Synchronized VPN/FireWall Modules must be managed by the same Management Module.
    SecuRemote connections can be synchronized.

Enable Exportable SKIP: If Enable Exportable SKIP (in the Encryption tab of the Properties Setup window) is checked, then if an internal VPN/FireWall Module has Local selected in the Key Manager tab of its SKIP Properties window, you must generate an exportable DH key for it (in its SKIP Properties window). Selective SKIP configuration (that is, some SKIP communications use exportable DH keys and some use non-exportable DH keys) can only be managed in the Rule Base.

Control channel encryption key If you change a Management Server’s control channel encryption key (for example, by using the fw putkey command), then you must restart any ELA proxy that is running on that Management Server. See "Uninstalling VPN-1/FireWall-1" on page 6 for information on how to stop the ELA proxy.

In a High Availability configuration, each VPN/FireWall Module’s license should be issued to its hostid or other unique ("heartbeat" or "configuration IP" interface), since any of the other interfaces can fail.

Do not rename a network object group that is used in the definition of a Logical Server.

Unix platforms — when remote modules are configured using the cpconfig program, if you try to add a new remote module you will not be able to see the list of previously configured modules. However, these modules are still defined and there is no need to reconfigure them. If you do reconfigure them, you must run fw putkey command again for each module.

backward compatibility feature:  If you are using the VPN-1/FireWall-1 Check Point 2000 backward compatibility feature to manage VPN-1/FireWall-1 Version 4.0 SP1 or SP2 FireWall Modules and you use Client Authentication rules, the following workaround must be applied:

a. Edit the file $FWDIR/lib/base.def (where FWDIR specifies the directory in which the VPN-1/FireWall-1 Version 4.0 software or VPN-1/FireWall-1 Check Point 2000 backward compatibility module is installed), replacing the lines:

define pm_prog [(UDPDATA+40+rpc_cred_len+rpc_ver_len),b]
#define pm_prot [(UDPDATA+48+rpc_cred_len+rpc_ver_len),b]

by the lines:

#define pm_prog [68, b]
#define pm_prot [68+8, b]

b. Reinstall the Security Policy on the VPN/FireWall Module.

fw expdate command — This command changes the expiration date of the users in the VPN-1/FireWall-1 users database. Any open GUI Client should be closed before running the command, otherwise the GUI will override the changes made by the command. On NT only, if fw expdate is executed while the Management Server was running, the Management Server should be restarted in order for the command to take effect.