Microsoft Active Directory databases are LDAP compliant so you can use
Firewall-1 to authenticate your users via LDAP. You can buy an account
management module license, the module is an add-on component for managing an
LDAP database however you can authenticate against an LDAP database (but
manage it externally) without buying this extra module.

Radius and SecurID dont require any extra software module, just enable them
as supported authentication schemes, create the server objects, configure
the external authentication server (for Radius configure each enforcement
module as a Radius client, for SecurID configure as an ACE client),
configure users and security rules etc. As of NG AI Firewall-1 supports all
1 - 63 RADIUS attributes.

Regards

Stu

-----Original Message-----
From: Ruiyuan Jiang [mailto:[EMAIL PROTECTED]
Sent: 08 January 2004 22:57
To: [EMAIL PROTECTED]
Subject: [FW-1] VPN Access with MS Active Directory


Hi, all

I am evaluating VPN remote access such as SecuRemote or Secure Client to
CheckPoint NG firewall. For remote user authentication, if I want users to
authenticate with their Microsoft Active Directory ID, what extra software
or CheckPoint's module do I have to purchase? How about Radius, SecureID,
etc.? Thanks in advance.


Ryan Jiang

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================




Please note that:

1. This e-mail may constitute privileged information. If you are not the intended 
recipient, you have received this confidential email and any attachments transmitted 
with it in error and you must not disclose, copy, circulate or in any other way use or 
rely on this information.
2. E-mails to and from the company are monitored for operational reasons and in 
accordance with lawful business practices.
3. The contents of this email are those of the individual and do not necessarily 
represent the views of the company.
4. The company does not conclude contracts by email and all negotiations are subject 
to contract.
5. The company accepts no responsibility once an e-mail and any attachments is sent.

http://www.activis.com


This annotation was added by the e-scan service.
http://www.activis.com
----------------------------------------------------------------------------------
This message has been checked for all known viruses by e:)scan.
For further information please contact [EMAIL PROTECTED]

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to