<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Smart console AD authentication  in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartConsole-AD-Authentication/m-p/32964#M92058</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Still not possible the way you want to do it.&lt;/P&gt;&lt;P&gt;See the documentation &lt;A href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_SecurityManagement_AdminGuide/162331.htm#o131966"&gt;R80.10 Management Admin Guide, Section: Configuring Authentication Methods for Administrators&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Same goes for&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_SecurityManagement_AdminGuide/162331.htm#o131966"&gt;R80.20 Management Admin Guide, Section: Configuring Authentication Methods for Administrators&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I did hear that request/question from every customer who was thinking about moving away from local OS accounts. And it is the first question that comes to mind, always.&lt;/P&gt;&lt;P&gt;I do struggle to understand this approach, however. I reckon that there is a very good reason behind this, though. I'm sure. 100%. No doubt.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could someone knowing(!) the reasons please elabotrate about this?&lt;/P&gt;&lt;P&gt;Maybe it is about, who has control over the authorizing system and it's security measures and options (2FA, etc.)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 04 Oct 2018 13:22:53 GMT</pubDate>
    <dc:creator>Carsten_Weber</dc:creator>
    <dc:date>2018-10-04T13:22:53Z</dc:date>
    <item>
      <title>SmartConsole AD Authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartConsole-AD-Authentication/m-p/32962#M92056</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello folks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have integrated Active directory with Checkpoint R80.10. So can I use the active directory user log in for smart console. I do not have radius server. Please let me know Is it possible and how?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Oct 2018 09:58:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartConsole-AD-Authentication/m-p/32962#M92056</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2018-10-04T09:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: Smart console AD authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartConsole-AD-Authentication/m-p/32963#M92057</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;You could use Microsoft NPS (Network Policy Server = Radius Server) on either DC or separate Server.&lt;/SPAN&gt;&lt;BR class="" /&gt;&lt;P class=""&gt;&lt;BR /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Oct 2018 10:20:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartConsole-AD-Authentication/m-p/32963#M92057</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2018-10-04T10:20:44Z</dc:date>
    </item>
    <item>
      <title>Re: Smart console AD authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartConsole-AD-Authentication/m-p/32964#M92058</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Still not possible the way you want to do it.&lt;/P&gt;&lt;P&gt;See the documentation &lt;A href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_SecurityManagement_AdminGuide/162331.htm#o131966"&gt;R80.10 Management Admin Guide, Section: Configuring Authentication Methods for Administrators&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Same goes for&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_SecurityManagement_AdminGuide/162331.htm#o131966"&gt;R80.20 Management Admin Guide, Section: Configuring Authentication Methods for Administrators&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I did hear that request/question from every customer who was thinking about moving away from local OS accounts. And it is the first question that comes to mind, always.&lt;/P&gt;&lt;P&gt;I do struggle to understand this approach, however. I reckon that there is a very good reason behind this, though. I'm sure. 100%. No doubt.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could someone knowing(!) the reasons please elabotrate about this?&lt;/P&gt;&lt;P&gt;Maybe it is about, who has control over the authorizing system and it's security measures and options (2FA, etc.)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Oct 2018 13:22:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartConsole-AD-Authentication/m-p/32964#M92058</guid>
      <dc:creator>Carsten_Weber</dc:creator>
      <dc:date>2018-10-04T13:22:53Z</dc:date>
    </item>
    <item>
      <title>Re: Smart console AD authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartConsole-AD-Authentication/m-p/32965#M92059</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A href="https://community.checkpoint.com/migrated-users/42335"&gt;Blason R&lt;/A&gt;, I actually had implemented the option told by &lt;A href="https://community.checkpoint.com/migrated-users/42232"&gt;Norbert Bohusch&lt;/A&gt; in my environment:&lt;/P&gt;&lt;P&gt;a Windows Server with the NPS role installed on a separate server of the domain controller (I believe putting the NPS in a DC is a big NO-NO).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also as Norbert says the NPS role is essentially a Radius server, so you have to follow the instructions for "Configuring a RADIUS Server for Administrators" from the Admin Guide:&lt;/P&gt;&lt;P&gt;- Create a Radius Server object with a shared secret on the SmartConsole&lt;/P&gt;&lt;P&gt;- In the NPS server create&amp;nbsp;a Radius Client with the Management/SmartCenter IP address and obviously the same shared secret from above&lt;/P&gt;&lt;P&gt;- Create a Connection Policy with at least a condition (for example the NAS IPv4 address as the IP address of mgmt) with EAP-MSCHAP as authentication method&lt;/P&gt;&lt;P&gt;- Create a Network Policy with also at least the same condition above (but I also configure a condition for the users must be members of an specific AD group)&lt;/P&gt;&lt;P&gt;- Create an administrator on the SmartConsole with a username format like &amp;lt;AD domain&amp;gt;\&amp;lt;AD user&amp;gt; and Radius as authentication method&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then you can login using the&amp;nbsp;&lt;SPAN&gt;&amp;lt;AD domain&amp;gt;\&amp;lt;AD user&amp;gt; as user name and your AD password as password.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hope it helped&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Oct 2018 18:28:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartConsole-AD-Authentication/m-p/32965#M92059</guid>
      <dc:creator>SantiagoPlatero</dc:creator>
      <dc:date>2018-10-11T18:28:58Z</dc:date>
    </item>
    <item>
      <title>Re: SmartConsole AD Authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartConsole-AD-Authentication/m-p/68720#M92060</link>
      <description>how did you get smartconsole to log in with AD? I can't find a good guide</description>
      <pubDate>Wed, 27 Nov 2019 19:55:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartConsole-AD-Authentication/m-p/68720#M92060</guid>
      <dc:creator>Smartin</dc:creator>
      <dc:date>2019-11-27T19:55:53Z</dc:date>
    </item>
    <item>
      <title>Re: SmartConsole AD Authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartConsole-AD-Authentication/m-p/68726#M92061</link>
      <description>You cannot directly authenticate SmartConsole with AD users.&lt;BR /&gt;You can, however, use a RADIUS server that is tied into AD (like Microsoft NPS) as a go-between.&lt;BR /&gt;The answer I've marked in this thread as "correct" is a good place to start.&lt;BR /&gt;</description>
      <pubDate>Wed, 27 Nov 2019 22:49:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartConsole-AD-Authentication/m-p/68726#M92061</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-11-27T22:49:14Z</dc:date>
    </item>
    <item>
      <title>Re: SmartConsole AD Authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartConsole-AD-Authentication/m-p/68750#M92062</link>
      <description>&lt;P&gt;For reference this has been discussed previously in another thread, see here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Management-Topics/Multi-domain-Admin-user-authentication-to-AD/td-p/23420" target="_blank"&gt;https://community.checkpoint.com/t5/General-Management-Topics/Multi-domain-Admin-user-authentication-to-AD/td-p/23420&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Nov 2019 07:38:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartConsole-AD-Authentication/m-p/68750#M92062</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2019-11-28T07:38:59Z</dc:date>
    </item>
    <item>
      <title>Re: SmartConsole AD Authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartConsole-AD-Authentication/m-p/68759#M92063</link>
      <description>There is a way in R80.20 and R80.30, but you have to ask for the activation method, with you local SE's.</description>
      <pubDate>Thu, 28 Nov 2019 08:34:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartConsole-AD-Authentication/m-p/68759#M92063</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-11-28T08:34:27Z</dc:date>
    </item>
    <item>
      <title>Re: SmartConsole AD Authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartConsole-AD-Authentication/m-p/109878#M92064</link>
      <description>&lt;P&gt;I just recently became aware of this SK that provides a mechanism for authenticating SmartConsole users with Active Directory.&lt;BR /&gt;It is supported from R80.20 JHF, but has some limitations, and thus&amp;nbsp;won't be appropriate in every situation.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk145392" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk145392&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 07:49:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartConsole-AD-Authentication/m-p/109878#M92064</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-02-05T07:49:51Z</dc:date>
    </item>
    <item>
      <title>Re: SmartConsole AD Authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartConsole-AD-Authentication/m-p/159931#M92065</link>
      <description>&lt;P&gt;To bring back an old post again, in R81 and R81.10 there seems to be a difference in the Kerberos part used underwater. Due to company policies we were forced to harden the AD server and ran into an issue when the following encryption types were disabled for the Kerberos authentication:&lt;/P&gt;
&lt;P&gt;DES_CBC_CRC,&amp;nbsp; DES_CBC_MD5,&amp;nbsp; RC4_HMAC_MD5&lt;/P&gt;
&lt;P&gt;Then we found that authentication to a R81 MDS was no longer working in a capture you see Kerberos errors with preauth_required, response_too_big and etype_nosupp&lt;/P&gt;
&lt;P&gt;At the same time authenticating to a R81.10 MDS worked just fine, so it seems to be a version related.&lt;/P&gt;
&lt;P&gt;Main question here: is there a way to force higher encryption types on the kerberos protocol?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 08:55:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartConsole-AD-Authentication/m-p/159931#M92065</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2022-10-19T08:55:13Z</dc:date>
    </item>
    <item>
      <title>Re: SmartConsole AD Authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartConsole-AD-Authentication/m-p/171856#M92066</link>
      <description>&lt;P&gt;Perhaps you already solved it, but this link looks to be the solution&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk178069&amp;amp;partition=Basic&amp;amp;product=Quantum" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk178069&amp;amp;partition=Basic&amp;amp;product=Quantum&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 09:56:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartConsole-AD-Authentication/m-p/171856#M92066</guid>
      <dc:creator>JanVC</dc:creator>
      <dc:date>2023-02-17T09:56:05Z</dc:date>
    </item>
  </channel>
</rss>

