<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>LINICKX.com</title><link>https://www.linickx.com/</link><description></description><lastBuildDate>Tue, 11 Dec 2012 09:35:00 +0000</lastBuildDate><item><title>Checkpoint, Gaia, TACACS - two lines of config</title><link>https://www.linickx.com/checkpoint-gaia-tacacs-two-lines-of-config</link><description>&lt;p&gt;If you have a checkpoint firewall, you probably know about
&lt;a href="http://www.checkpoint.com/gaia/"&gt;Gaia&lt;/a&gt;... and if you have more than one
firewall admin, you probably want to individually authenticate them to
the operating system (&lt;em&gt;as apposed to a encrypted file of usernames &amp;amp;
passwords which get's passed around the office&lt;/em&gt;)&lt;/p&gt;
&lt;pre&gt;&lt;code&gt; add rba role TACP-0 domain-type System all-features
 set aaa tacacs-servers authentication server 10.10.10.10 key mysecretkey
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;What you need to know about the above...&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;If a user can successfully authenticate by TACACS they become a
    super user, if you need different roles read up on "role based
    administration", &lt;code&gt;TACP-15&lt;/code&gt; and the &lt;code&gt;enable_tacacs&lt;/code&gt; command.&lt;/li&gt;
&lt;li&gt;The config has been tested on Cisco ACS 5.4, the default TACACS
    "&lt;code&gt;default device administration&lt;/code&gt;" profile works with no changes.&lt;/li&gt;
&lt;li&gt;This is tacacs authentication only, authorization is handled by the
    local RBA.&lt;/li&gt;
&lt;/ul&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">nick</dc:creator><pubDate>Tue, 11 Dec 2012 09:35:00 +0000</pubDate><guid isPermaLink="false">tag:www.linickx.com,2012-12-11:checkpoint-gaia-tacacs-two-lines-of-config</guid><category>acs</category><category>checkpoint</category><category>Cisco</category><category>gaia</category><category>tacacs</category></item><item><title>CheckPoint: "Encryption Failure: according to the policy the packet should not have been decrypted."</title><link>https://www.linickx.com/checkpoint-encryption-failure-according-to-the-policy-the-packet-should-not-have-been-decrypted</link><description>&lt;p&gt;The &lt;a href="https://supportcenter.checkpoint.com/supportcenter/LoginRedirect.jsp?toURL=eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk21571%20"&gt;checkpoint sk
article&lt;/a&gt;
isn't that helpful... what it should say is... If you have your
encryption domain set as "&lt;em&gt;defined by topology&lt;/em&gt;", then check your
topology!&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">nick</dc:creator><pubDate>Mon, 19 Nov 2012 15:59:00 +0000</pubDate><guid isPermaLink="false">tag:www.linickx.com,2012-11-19:checkpoint-encryption-failure-according-to-the-policy-the-packet-should-not-have-been-decrypted</guid><category>checkpoint</category><category>firewall</category><category>Security</category><category>vpn</category></item><item><title>Check Point CCSE R70</title><link>https://www.linickx.com/check-point-ccse-r70</link><description>&lt;p&gt;&lt;a href="/files/2011/03/CheckPoint_CCSE-R70.png"&gt;&lt;img alt="CCSE R70" src="/files/2011/03/CheckPoint_CCSE-R70-300.png" title="Check Point CCSE R70" /&gt;&lt;/a&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Nick Bettison</dc:creator><pubDate>Wed, 09 Mar 2011 01:01:00 +0000</pubDate><guid isPermaLink="false">tag:www.linickx.com,2011-03-09:check-point-ccse-r70</guid><category>certificates</category><category>checkpoint</category><category>CCSE</category><category>R70</category></item><item><title>Checkpoint Nokia, How to enable SSH thru the default filter.</title><link>https://www.linickx.com/checkpoint-nokia-how-to-enable-ssh-thru-the-default-filter</link><description>&lt;p&gt;I had lost this bookmark, saved here so I don't loose it again :)&lt;/p&gt;
&lt;blockquote&gt;
&lt;ul&gt;
&lt;li&gt;Solution Title: How do I control / change access using
    defaultfilter and initialpolicy?&lt;/li&gt;
&lt;li&gt;Solution ID:
    &lt;a href="https://supportcenter.checkpoint.com/supportcente/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk41117"&gt;sk41117&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;
&lt;p&gt;There are various options given in the article, this...&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;ipso[nick]# cp -p $FWDIR/conf/initial_module.pf $FWDIR/conf/initial_module.pf.OLD
ipso[nick]# cp $FWDIR/lib/defaultfilter.ipso $FWDIR/conf/initial_module.pf
ipso[nick]# comp_init_policy -g
initial_module:
Compiled OK.
ipso[nick]#
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;... will do in most cases!&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">nick</dc:creator><pubDate>Fri, 04 Sep 2009 09:56:00 +0100</pubDate><guid isPermaLink="false">tag:www.linickx.com,2009-09-04:checkpoint-nokia-how-to-enable-ssh-thru-the-default-filter</guid><category>Blog</category><category>checkpoint</category><category>firewall</category><category>ipso</category><category>Nokia</category><category>Security</category></item><item><title>Check Point CCSE</title><link>https://www.linickx.com/check-point-ccse</link><description>&lt;p&gt;&lt;a href="/files/2002/07/CheckPoint_CCSE.png"&gt;&lt;img alt="Check Point CCSE" src="/files/2002/07/CheckPoint_CCSE-300.png" title="Check Point CCSE" /&gt;&lt;/a&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Nick Bettison</dc:creator><pubDate>Tue, 02 Jul 2002 03:03:00 +0100</pubDate><guid isPermaLink="false">tag:www.linickx.com,2002-07-02:check-point-ccse</guid><category>certificates</category><category>checkpoint</category><category>CCSE</category></item><item><title>Check Point CCSA</title><link>https://www.linickx.com/check-point-ccsa</link><description>&lt;p&gt;&lt;a href="/files/2002/07/CheckPoint_CCSA.png"&gt;&lt;img alt="Check Point CCSA" src="/files/2002/07/CheckPoint_CCSA-300.png" title="Check Point CCSA" /&gt;&lt;/a&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Nick Bettison</dc:creator><pubDate>Tue, 02 Jul 2002 02:03:00 +0100</pubDate><guid isPermaLink="false">tag:www.linickx.com,2002-07-02:check-point-ccsa</guid><category>certificates</category><category>checkpoint</category><category>CCSA</category></item><item><title>Check Point CCSA 2000</title><link>https://www.linickx.com/check-point-ccsa-2000</link><description>&lt;p&gt;&lt;a href="/files/2001/07/CheckPoint_CCSA-2000.png"&gt;&lt;img alt="CCSA 2000" src="/files/2001/07/CheckPoint_CCSA-2000-300.png" title="Check Point CCSA 2000" /&gt;&lt;/a&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Nick Bettison</dc:creator><pubDate>Mon, 09 Jul 2001 01:01:00 +0100</pubDate><guid isPermaLink="false">tag:www.linickx.com,2001-07-09:check-point-ccsa-2000</guid><category>certificates</category><category>checkpoint</category><category>CCSA</category></item><item><title>Check Point CCSE 2000</title><link>https://www.linickx.com/check-point-ccse-2000</link><description>&lt;p&gt;&lt;a href="/files/2001/07/CheckPoint_CCSE-2000.png"&gt;&lt;img alt="CCSE 2000" src="/files/2001/07/CheckPoint_CCSE-2000-300.png" title="Check Point CCSE 2000" /&gt;&lt;/a&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Nick Bettison</dc:creator><pubDate>Mon, 09 Jul 2001 01:01:00 +0100</pubDate><guid isPermaLink="false">tag:www.linickx.com,2001-07-09:check-point-ccse-2000</guid><category>certificates</category><category>checkpoint</category><category>CCSA</category></item></channel></rss>