Hi, I tried NEW-RADIUS and allowed PAP, I still get the same results. 8( At this point I'm quite convinced that NG FP3 hotfix 1 is broken. I see some TCP Out of State packets dropped by FW1 before rejecting connection in FW1 log.
Regards, Norman ----- Original Message ----- From: "Ted Serreyn" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Wednesday, March 12, 2003 9:33 AM Subject: Re: [FW-1] radius help make sure you use new-radius for the protocol for win2k and you modifiy the ias profile to allow PAP (unencrypted) authentication. Ted On Wed, 2003-03-12 at 10:17, Norman Zhang wrote: Hi Lars, I'm trying to authenticate local users for outgoing http access. When users tried to access the web they are challenged by FW for their NT password. FW does the authentication by sharing a secret with a BDC RADIUS server from the localnet. The users file that I refered to resides in IAS folder (http://www.phoneboy.com/fom/fom.pl?_highlightWords=radius&file=435). I doubt it is much useful, as I didn't make any change in it before, and it worked. Regards, Norman ----- Original Message ----- From: "Lars Troen" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Wednesday, March 12, 2003 2:19 AM Subject: Re: [FW-1] radius help Uhm.. I don't think I quite understand what you're trying to do. When you're mentioning users file, do you mean userc.C as in SecureClient? Or are you trying to give access to web resources only for authenticated users (no SecureClient/Securemote)? Lars -----Original Message----- From: Norman Zhang [mailto:[EMAIL PROTECTED] Sent: Wed 12-Mar-03 8:15 AM To: [EMAIL PROTECTED] Cc: Subject: Re: [FW-1] radius help Hi Lars, No. I can't even see the very first page. I wish I get prompted for every page that I'm trying to browse, which I can use implicit authentication to bypass the prompt (correct?). Would you mind posting your configurations? Do I need to set DEFAULT Auth-Type = System, User-Service-Type = Login-User in users file? I never had this on previous configuration, and it worked fine. Do you mind posting your configuration? I think I'm doing something very stupid 8( Regards, Norman ----- Original Message ----- From: "Lars Troen" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Tuesday, March 11, 2003 6:02 PM Subject: Re: [FW-1] radius help aha.. you're trying to use http with user authentication! You must setup the firewall as a proxy in the browser, or you must authenticate for each page you're loading.. Lars -----Original Message----- From: Norman Zhang [mailto:[EMAIL PROTECTED] Sent: Tuesday, March 11, 2003 20:44 To: [EMAIL PROTECTED] Subject: Re: [FW-1] radius help Hi Lars, I did test the options that you specified, but I still cannot get internet access for internal net users. There's no NAT between the RADIUS host and clients. NAT is only used for internal net users to access the web. After putting in the rule [EMAIL PROTECTED]>any-->any-->http-->user authentication. I see the event viewer shows successful authentication, but FW-1 keeps prompting for user name and password, and replies that I have the wrong user name or password. The denied access that I got before is from ntradping.exe. It is still happening regardless of the rule that I put in. Do you have any ideas? I'm running NG FP3 hotfix 1 on W2K sp3, and RADIUS host is on a NT4.0 sp6a BDC. Regards, Norman --- Norman, - Make sure you're not natting the communication between the firewall and the radius server. - Make both the internal nic and the licensed nic a radius client. I have setup working configs with both FP2 and FP3 to NT4 and w2k IAS. Lars -----Original Message----- From: Norman Zhang [mailto:[EMAIL PROTECTED] Sent: Friday, March 07, 2003 17:06 To: [EMAIL PROTECTED] Subject: [FW-1] radius help Hi, I have done some further troubleshooting. I see the RAIDUS packets from port 1645 that originate from firewall to RADIUS server received reject. But behind the LAN on a different machine in the same subnet, I received accept. My firewall is set to allow outgoing traffic. Are there other properties that I need to set in NG FP3? Regards, Norman ----- Original Message ----- From: "Norman Zhang" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Monday, March 03, 2003 5:45 PM Subject: [FW-1] radius help Hi, I had this working in 4.1 but I can't get RADIUS to work in NG FP3. I installed IAS from NT 4.0 Option Pack then applied midcamp.exe and iassp6-x86.exe from MS. My firewall rule is [EMAIL PROTECTED] -->any-->any-->http-->user authentication The RADIUS clients file is setup as FWIntIP mySecret and users as DEFAULT Internal-Proxy-Server = "DLL C:\Program Files\IAS\authsam.dll" Framed-Protocol = PPP Framed-Routing = Send Service-Type = Framed Event Viewer displays the following with Event ID: 8207, Source: AuthSrv, Type: Warning, Category: Malformed Packet Unknown Client: Source = FWIntIP:2912 Code = Access-Request Identifier = 64 User-Name = InternalUser Password = ****** Service-Type = Authenticate-Only NAS-IP-Address = FwExtIP Would someone please give some pointers here? Regards, Norman --- Hi, I have a RADIUS on a NT 4.0 BDC. I need to able to authenticate NG FP3 with the RADIUS, but I seem to forget what settings that I need to change the users file. I tried to follow, DEFAULT Auth-Type = System, User-Service-Type = Login-User as described in http://www.phoneboy.com/fom/fom.pl?_highlightWords=radius&file=435. But those two attributes does not seem to exist in RADIUS (I'm using the one came with NT 4.0 Option Pack (with appropriate fixes). Does anyone remember what I need to change in the configuration file to get this working? ================================================= To set vacation, Out Of Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
