<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mobile Access - AD users not belonging to an access role have access to mobile access portal in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-AD-users-not-belonging-to-an-access-role-have/m-p/101445#M10169</link>
    <description>&lt;P&gt;It may be depending on how you've configured it.&lt;BR /&gt;Screenshots of the relevant configuration would be helpful.&lt;/P&gt;</description>
    <pubDate>Mon, 09 Nov 2020 01:23:15 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-11-09T01:23:15Z</dc:date>
    <item>
      <title>Mobile Access - AD users not belonging to an access role have access to mobile access portal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-AD-users-not-belonging-to-an-access-role-have/m-p/101437#M10168</link>
      <description>&lt;P&gt;Hi team,&lt;/P&gt;&lt;P&gt;I need your help on this matter.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the environment&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;R80.40&lt;/LI&gt;&lt;LI&gt;Dedicated Management&lt;/LI&gt;&lt;LI&gt;Cluster of 5600&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;We are using MS Active Directory Integration&amp;nbsp;with Access Mobile Access and we defined access role.&lt;/P&gt;&lt;P&gt;But, AD users not belonging to an access role have access to mobile access portal, why&amp;nbsp;? In the log we see in the usergroup_-"user do not belong to any group".&lt;/P&gt;&lt;P&gt;I want to know if this is an expected behaviour&amp;nbsp;? from my understanding, an Access Role is how the firewall determines what users are allowed access and those that are not define will be dropped.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Sun, 08 Nov 2020 19:58:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-AD-users-not-belonging-to-an-access-role-have/m-p/101437#M10168</guid>
      <dc:creator>constant69</dc:creator>
      <dc:date>2020-11-08T19:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - AD users not belonging to an access role have access to mobile access portal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-AD-users-not-belonging-to-an-access-role-have/m-p/101445#M10169</link>
      <description>&lt;P&gt;It may be depending on how you've configured it.&lt;BR /&gt;Screenshots of the relevant configuration would be helpful.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 01:23:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-AD-users-not-belonging-to-an-access-role-have/m-p/101445#M10169</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-11-09T01:23:15Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - AD users not belonging to an access role have access to mobile access portal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-AD-users-not-belonging-to-an-access-role-have/m-p/101472#M10170</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;Thank for your reply.&lt;/P&gt;&lt;P&gt;This is a basic configuration in R80.40 ( I have the same behavior in my lab R80.10)&lt;/P&gt;&lt;P&gt;- 2 Access roles&lt;/P&gt;&lt;P&gt;- 2 rules with the both access roles in the source and mobile access application&lt;/P&gt;&lt;P&gt;I have attached screenshots&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 12:49:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-AD-users-not-belonging-to-an-access-role-have/m-p/101472#M10170</guid>
      <dc:creator>constant69</dc:creator>
      <dc:date>2020-11-09T12:49:56Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - AD users not belonging to an access role have access to mobile access portal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-AD-users-not-belonging-to-an-access-role-have/m-p/101478#M10171</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/43988"&gt;@constant69&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;are the users with no group-mebership able to login only and did not see any MOB-defined application ?&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 10:24:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-AD-users-not-belonging-to-an-access-role-have/m-p/101478#M10171</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-11-09T10:24:45Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - AD users not belonging to an access role have access to mobile access portal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-AD-users-not-belonging-to-an-access-role-have/m-p/101494#M10172</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The users with no group-membership are able to login only and they did not see any MOB-defined application,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 12:47:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-AD-users-not-belonging-to-an-access-role-have/m-p/101494#M10172</guid>
      <dc:creator>constant69</dc:creator>
      <dc:date>2020-11-09T12:47:44Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - AD users not belonging to an access role have access to mobile access portal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-AD-users-not-belonging-to-an-access-role-have/m-p/101508#M10173</link>
      <description>&lt;P&gt;Ok, looks like expected behaviour.&lt;/P&gt;
&lt;P&gt;If the gateway is member of the remote access community and the "participant user groups" ist set to "all users" this is working as designed.&lt;/P&gt;
&lt;P&gt;The users can authenticate but have no access to any MOB application or VPN connection.&lt;/P&gt;
&lt;P&gt;If you want to limit to a specific usergroup you have to define them and replace the "all users". If you don't use any remote-access VPN on your gateway (SSL extender, checkpoint mobile etc.) you can remove the gateway from the remote access community.&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 13:40:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-AD-users-not-belonging-to-an-access-role-have/m-p/101508#M10173</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-11-09T13:40:54Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - AD users not belonging to an access role have access to mobile access portal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-AD-users-not-belonging-to-an-access-role-have/m-p/101514#M10174</link>
      <description>&lt;P&gt;Thank for your help on this matter.&lt;/P&gt;&lt;P&gt;To sum up, as we cannot select Access Roles, the following procedure is relevant&lt;BR /&gt;1) Create a ldap group that containt the AD users allowed&lt;BR /&gt;2) Then, select the previous ldap group in the remote access community&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 13:48:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-AD-users-not-belonging-to-an-access-role-have/m-p/101514#M10174</guid>
      <dc:creator>constant69</dc:creator>
      <dc:date>2020-11-09T13:48:24Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - AD users not belonging to an access role have access to mobile access portal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-AD-users-not-belonging-to-an-access-role-have/m-p/101637#M10175</link>
      <description>&lt;P&gt;Hi Wolfgang,&lt;/P&gt;&lt;P&gt;Thank for your help on this matter: that solved my issue!&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2020 15:02:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-AD-users-not-belonging-to-an-access-role-have/m-p/101637#M10175</guid>
      <dc:creator>constant69</dc:creator>
      <dc:date>2020-11-10T15:02:34Z</dc:date>
    </item>
  </channel>
</rss>

