Nortel Switched Firewall 2.3.3 User’s Guide and Command Reference
Initial setup
81
213455-L, October 2005
Enabling SecurID authentication for Check Point FireWall-1 users
To enable SecurID authentication for Check Point FireWall-1 users, perform the following
steps:
1.
Create a new user group.
2.
Create a new user.
3.
Add the new user to the new group.
4.
From the Authentication tab, select SecurID for the authentication scheme.
The newly created user is authenticated using the ACE server through the Firewalls by user
name and passcode from the token card.
Rule base for user authentication with SecurID
The following table is a rule base for user authentication with SecureID.
Rule 1 challenges users from any location trying to access any service.
Rule 2 is not required if the Firewall is configured to allow outgoing packets as part of the
Global Policy Properties.
Rule 3 drops all other packets.
N
OTE
–
The SecureID user name must exist on the web, FTP, or Telnet server.
Rule base for client authentication with SecurID
With client authentication, an administrator can grant access a specific source. For SecurID
users, client authentication permits authentication to the Firewall once, through HTTP or
Telnet, then opens any number of connections for any service, while the authentication is valid
for any Administrator-defined duration.
Rule
number
Source
Destination VPN
Service
Action
Track
1
kevlar@Any
* Any
Any Traffic Authenti-
cated
User Auth Log
2
ACE_Server
Cluster _HA
* Any
Any Traffic Securid
Accept
Log
3
* Any
* Any
Any Traffic * Any
Drop
None