Configuring a Checkpoint firewall to work with SecurID
2 years ago
Originally Published: 2000-12-08
Article Number
000055582
Applies To
Check Point Firewall-1
RSA ACE/Server
Authentication Manager 6.1
CheckPoint VPN
Issue
Configuring a Checkpoint firewall to work with SecurID
Error: "SecurID is not supported"
Passcode incorrect
Resolution
If you cannot authenticate, know that the sdopts.rec file appears to be ignored, so the workaround is to use the MAIN CheckPoint IP address, usually the External or Management interface (run the hostname command on the checkpoint, and ping CheckPoint by hostname on the CheckPoint itself,and see what IP comes back), use this IP as the Agent Host IP and add the Internal IP address as a Secondary Node
(This is a Checkpoint/ACE configuration) The authentication type needs to be set in the network object.

Do the following:

- The administrator needs to bring up the Firewall-1 main GUI.
- Select the Objects menu.
- Select firewall.
- Select Auth (authenticate).
- Select the type, in this case SecurID.

Also make sure the sdconf.rec file is in the /var/ace directory (a symbolic link to this directory may need to be made).  

The Implementation Guide on the RSA Web site mentions this, but only if the firewall and the ACE/Server are on the same system. In this case, the firewall and the ACE/Server were different systems.

See also RSA Security's Implementation Guides for further information about supported firewalls
Notes
some imp guides say sdopts.rec is not used in checkpoint. in newer checkpoint r70, it is used. so it is possible to try sdopts.rec