10-22-2007 04:17 AM - edited 07-03-2021 02:48 PM
Dear Support,
Looking at deploying PEAP, via WZC client and MS-CHAP v2.
The desktop team would like to know what rules need to be configured on the Integrity client for PEAP authentication.
Can anyone help me please?
thanks in advance.
I always rate helpful posts.
Regards, Adrian.
Solved! Go to Solution.
10-22-2007 07:25 AM
802.1x authentication happens (primarily) at layer 2, there are no ports to open on the client(s).
In fact, prior to 802.1x authentication you dont get access to the network medium past layer 1; your clients wont even have IP address yet (or be allowed DHCP requests).
Erik
10-22-2007 04:33 AM
A WPA suite is always a good option for message integrity. Both WPA/WPA2 do MIC through TKIP and AES, which would be an answer to your query.
10-22-2007 05:16 AM
Many thanks for the update, I total agree with your recommendations, but from a client firewall perspective (i.e. the integrity client) what ports would i need to allow for peap authentication ... i.e. is it over http (tcp port 80), https (tcp port 443), etc.
Your assistance is appreciated.
Thanks again.
Regards,
Adrian
10-22-2007 07:25 AM
802.1x authentication happens (primarily) at layer 2, there are no ports to open on the client(s).
In fact, prior to 802.1x authentication you dont get access to the network medium past layer 1; your clients wont even have IP address yet (or be allowed DHCP requests).
Erik
10-22-2007 07:36 AM
Many thanks Erik, so hopefully no configuration necessary of the integrity client.
many thanks adrian
10-22-2007 07:50 AM
That's correct, there should be no client (software) firewall configuration.
Erik
10-22-2007 08:00 AM
I wish it was as simple as that, unfortunately all laptops (the wireless users) will have the integrity client, so not sure where to go from here, as since checkpoint has purchased integrity the free support has gone!
But as you have pointed out, this happens at layer 2, so not sure if the integrity client gets involved at this point?
thanks again.
regards adrian
10-22-2007 08:06 AM
Correct me if I'm wrong (I'm not very familier with these client firewall products), but as I understand it they are all layer-3/4 firewalls.
That being the case none of them will effect the 802.1x authentication/authorization process.
10-22-2007 08:23 AM
I agree, but for some reason the windows team who do the image for the laptop need me to provide them with what is needed on the integrity client. By as it is layer 2 i'm not sure if rules need to be defined. Suspect the only way to be sure would be to put a sniffer on the client.
Thanks again for your assistance.
regards, Adrian.
10-22-2007 08:41 AM
I know this isnt exactly an all encompasing list but it's about the best thing I could find:
http://www.checkpoint.com/products/enterprise/comparison_chart.html
For what it's worth the Integrity firewall does do some application layer filtering.
I would tell your Windows build team that no settings are needed and just test prior to deployment (you're going to know quickly if it isnt working). I would be very suprised if the client had issues because of this.
10-22-2007 11:25 AM
Hi Eric,
Thanks again for your assistance, this is a good page to work from.
Thanks again for your efforts it is appreciated.
All the best for the testing!
Thanks and regards,
Adrian.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide