Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
AleLovaz82
Collaborator
Collaborator

Change password with "Checkpoint Password"

Hi, 

a dumb question : some of my vpn user still use local user with Checkpoint Password as auth method, is possible to make them change their password by themself without contacting firewall administrator ?

Thx in advance


0 Kudos
11 Replies
the_rock
Legend
Legend

Thats valid question. See attached. Min is 8 characters.

Andy

0 Kudos
AleLovaz82
Collaborator
Collaborator

Andy in that way a user that doesn't have a smart console account can't manage his own password,that operation can be done only by smart console user

I have a lot of vpn user that use only vpn but don't need to access the smart console.

0 Kudos
the_rock
Legend
Legend

Sorry, maybe I misunderstood. Is it local CP user? If not, what sort of account is it?

Andy

0 Kudos
AleLovaz82
Collaborator
Collaborator

it's a simple local user created on smart console used into a local user group ,used into an access-role item ,and it's used only to access the vpn.
SecurityAdmins can change the password for the users, but we don't want to do it ,we want the user to be able to manage his own password .
( I "forced" a lot of user to user AD login to access the vpn ,but "temporary consultant" can't have one )

0 Kudos
the_rock
Legend
Legend

K, gotcha. Personally, I dont know of any way to do that unless they have smart console access and read-only wont do it, unless you create custom admin profile where they can edit that setting.

Andy

0 Kudos
AleLovaz82
Collaborator
Collaborator

but a user should be able to change only is own password,not other user's password
I suppose that the profile will allow me to change that setting or not,but not to change only for the logged you.
I'll give a look and update the thread

0 Kudos
the_rock
Legend
Legend

Yes, but keep in mind, you can NOT do that from client itself, there is no option on endpoint vpn to do so.

Andy

0 Kudos
AleLovaz82
Collaborator
Collaborator

i know that ,but it's better that works as helpdesk for almost one hundred of user 🙂
All local users need to change their password because password policy changed with our new vpn based on 81.20 ,and the old vpn gateway was 80.40  
anyway for our new security policy we are not allowed to know user password...so I have to find a way 

0 Kudos
the_rock
Legend
Legend

I looked at custom admin profile in smart console, but dont see spefic setting for this. Let me know what you find, maybe TAC can confirm as well.

Andy

0 Kudos
AleLovaz82
Collaborator
Collaborator

sorry , i forgot...the admin profile is not on option , i should create a 2nd user for each person to log into the MDS / CMA as admin.

I think i'll do a script to change the password for them generatinc a random one and to send it using an email.

In this way it will be easy for me,and it will respect all the security policy

 

the_rock
Legend
Legend

Thats the best option, I agree.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events