Hello,

We would like to start to authenticate our internal users for use of
external resources (i.e. internet usage). We are currently running NG
(R55) and using a Win2k box for IAS [RADIUS] authentication of our VPN
users.

Besides building all of our users into SmartConsole to authenticate
against the FW-1 user base is there a way I can make my RADIUS box allow
the internal users out (logging the connection) but not let them VPN in
also?

As I see it, when I add the policy to allow access in IAS it will not
matter from what interface the user hits the CP box from. FW-1/VPN-1
will look to IAS for authentication, IAS will accept the connection as a
valid user, and CP will allow the data through; wither the user is
setting at their machine inside the building or sitting at home with a
rouge VPN connection.

The only solution I can see right now is to implement two separate
RADIUS servers. One to authenticate internal users wishing to access
external resources, and one to authenticate valid external users wishing
to initiate a VPN connection with the network.

Any feedback is, of course, appreciated.

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to