156-215.80 · Question #242
You find that Users are not prompted for authentication when they access their Web servers, even though you have created an HTTP rule via User Authentication. Choose the BEST reason why.
The correct answer is B. Another rule that accepts HTTP without authentication exists in the Rule Base. Check Point processes rules top-to-bottom with a first-match policy, so a permissive HTTP rule above the User Authentication rule will silently allow traffic without triggering authentication.
Question
You find that Users are not prompted for authentication when they access their Web servers, even though you have created an HTTP rule via User Authentication. Choose the BEST reason why.
Options
- AYou checked the cache password on desktop option in Global Properties.
- BAnother rule that accepts HTTP without authentication exists in the Rule Base.
- CYou have forgotten to place the User Authentication Rule before the Stealth Rule.
- DUsers must use the SecuRemote Client, to use the User Authentication Rule.
How the community answered
(44 responses)- A2% (1)
- B80% (35)
- C14% (6)
- D5% (2)
Why each option
Check Point processes rules top-to-bottom with a first-match policy, so a permissive HTTP rule above the User Authentication rule will silently allow traffic without triggering authentication.
The 'cache password on desktop' option affects credential caching for subsequent connections after an initial successful authentication, not whether users are prompted in the first place.
Check Point's rule base uses a first-match algorithm - if a rule accepting HTTP traffic without any authentication action exists above the User Authentication rule, connections match that rule first and are permitted without prompting for credentials. The User Authentication rule is never reached for that traffic.
The Stealth Rule protects the firewall gateway itself from direct access; its position relative to the User Authentication rule does not affect whether users are prompted when accessing web servers.
User Authentication operates as a proxy-based mechanism for standard HTTP and does not require the SecuRemote client; SecuRemote is used for encrypted VPN tunnels and Client Authentication scenarios.
Concept tested: Check Point rule base first-match order and User Authentication
Source: https://sc1.checkpoint.com/documents/R77/CP_R77_Firewall_AdminGuide/html_frameset.htm
Topics
Community Discussion
No community discussion yet for this question.