View a detailed demonstration on how SafeWord for Check Point works. |
Request an evaluation package. |
Get contact information for Secure Computing Corporation. |
Back to SafeWord for Check Point Home Page. |
|
|
Home -> Product Info -> Product Brief
SafeWord® for Check Point Product Overview
Strong authentication designed for Check Point systems
Eliminate the password risk
-
Positively identify your Check Point VPN users
-
Easy, fast installation
-
Token-generated passcodes change every time you log in
-
Seamless integration with Check Point VPNs
-
Installs on your existing hardware
SafeWord for Check Point
is the first strong authentication product
specifically designed to protect Check Point
VPN products. SafeWord® for Check Point
protects your critical network systems by
positively identifying users before allowing
them to make a VPN connection. The
system includes tokens that generate new
passcodes with every user login, robust and
scalable authentication server software, and
streamlined management through the Check
Point user management system, effectively
eliminating the password risk.
Passwords are the weakest link in your security
With Check Point VPN solutions, users can
access their networks from anywhere in the
world. Many organizations identify users with
only fixed passwords. But if you rely on passwords
for security, it's easy for outsiders to
break into your network. Passwords can easily
be hacked using a wide variety of attacks,
including sniffing, brute force attacks, dictionary
attacks, personal information gathering,
and even tricking users into revealing their
passwords. Industry experts estimate that
around 40 percent of companies' network
passwords can be hacked within five minutes.
Conventional wisdom says passwords
should be made more complicated (one government
agency has a password policy that's
30 pages long!), but the best password policy
can be undermined by a simple Post-it. The
practical reality is that complex passwords are
more likely to be written down, taped to monitors,
or hidden under keyboards. Or your
users will just forget their complex password,
making your help desk costs soar.
The best solution for VPNs: strong authentication
SafeWord for Check Point provides strong
authentication-a simple and effective way to
eliminate the risks of passwords for network
access using Check Point VPNs.
To understand strong authentication,
think of your ATM card. When you withdraw
money from your bank you use two security
factors-something you have (your card)
and something you know (your PIN).
You probably wouldn't want your bank to
allow withdrawals with just a password. Yet
many VPNs-IPSec and SSL-based-that
provide access to extremely valuable data,
proprietary information, and mission-critical
applications are protected only by one factor:
a weak password.
SafeWord for Check Point delivers security
through tokens that generate single-use passcodes.
Each user is assigned a token that can
generate millions of unique codes based on an
internal secret key. To log onto the network,
the user simply pushes a button on the token
to generate the next passcode, then enters that
one-time code along with a memorized PIN.
The robust SafeWord authentication server
verifies each token-generated passcode, allowing
access only to users with valid codes and
PINs. After being used once, a one-time passcode
is then useless, eliminating the risk of
outsiders stealing, copying, or reusing them, as
they could with regular passwords.
 |
|
SafeWord tokens generate new passcodes for every user login |
Simple management without redundant user accounts
SafeWord for Check Point installs rapidly and
can be run on servers you already have in your
network. Where other authentication systems
can require extensive training, additional hardware,
and complex configuration, SafeWord
for Check Point can be installed in less than
30 minutes, and snaps seamlessly into your
existing Check Point user management system.
SafeWord for Check Point tightly integrates
with both the Check Point User
Management system and Microsoft Active
Directory. It provides unprecedented ease of
management compared to other authentication
products. Because the product utilizes
existing user records in either Check Point
User Management or Active Directory, there is
no need to create redundant user accounts in a
separate database, saving administrative time
and money.
In fact, SafeWord for Check Point is
completely managed through plug-ins to the
management consoles, allowing you to easily
assign tokens to users, manage user PINs,
import token records, generate emergency
backup passwords, and test tokens.
 |
|
Installing SafeWord for Check Point is quick and easy. |
Dramatically reduce the time and cost of deployment
SafeWord for Check Point also greatly
simplifies the process of deploying tokens to
your end-users. The embedded User Center
allows your users to self-enroll tokens, manage
and update their PINs, and test their authenticators.
This optional self-enrollment
compatibility can save your organization more
than 80% of the cost typically associated with
assigning and distributing tokens.
Requirements
SafeWord for Check Point requires a Check
Point VPN system in place, with users
managed either in Check Point User
Management or Microsoft Active Directory.
 |
|
The SafeWord plug-in to Check Point's User Management System. |
Operational prerequisites
-
Microsoft Windows 2000 server or Microsoft Windows 2003 server
-
Internet Explorer 5.0 or later
-
Access to the Internet
-
Management server:
-
Check Point VPN-1®/FireWall-1® Management Server, or
-
Windows 2000/2003 domain (Active Directory)
Hardware Requirements
-
256 MB RAM (minimum); 512 MB (recommended)
-
300 MB of disk space (minimum); 3 GB (recommended)
Protecting other applications?
If you need to protect other resources or
multiple remote access methods, such as Web,
wireless, dialup, legacy systems, or networks
applications, you may want to consider other
SafeWord products.
SafeWord PremierAccess
is an award-winning strong authentication
and access control solution for enterprises. It
protects access to Web, Citrix, VPN, dial-up,
and other network applications. Many
authentication options are available, including
PIN-protected hardware tokens, software
tokens, smart cards, digital certificates, and
MobilePass™, which sends one-time passcodes
to your cell phone or pager.
For more information on all Secure Computing
products, please visit
http://www.securecomputing.com.
|