From: cisco4ng <cisco4ng AT YAHOO DOT COM>
Reply-To: Mailing list for discussion of Firewall-1
<FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Subject: Re: [FW-1] SecurID Config
Date: Wed, 28 Jun 2006 19:27:40 -0700
Hi,
The problem with Radius to proxy the auth requesto RSA is that you need
a
Radius server to do this. Furthermore, RSA ACE Server also comes with
native radius so you don't really need to another radius box for proxy.
The problem with this solution is that radius is supported for P-1
authentication
in NGx R60 or higher. It is NOT supported for NG with AI or lower.
My 2c.
"Larson, Todd (LNG-DAY)" <Todd.Larson AT LEXISNEXIS DOT COM> wrote:
Have you thought about using Radius to proxy the auth request to RSA,
it's much easier.
-----Original Message-----
From: Mailing list for discussion of Firewall-1
[mailto:FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM] On Behalf Of Erin
Young
Sent: Wednesday, June 28, 2006 11:59 AM
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Subject: Re: [FW-1] SecurID Config
I've tried the method using the vip defined in the agent host and no
luck,
so i am know going to the next method, a seperate agent host for each of
the
Nokia's. I have two sets of documentation from checkpoint and one does
not
state anyhting about generating the node secret file for the agent host
while the other one does. Which is correct?
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================
---------------------------------
How low will we go? Check out Yahoo! Messenger?s low PC-to-Phone call
rates.
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================