<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: rule with access role that not match in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rule-with-access-role-that-not-match/m-p/93427#M10600</link>
    <description>&lt;P&gt;Can be the case&lt;/P&gt;</description>
    <pubDate>Wed, 05 Aug 2020 13:44:34 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2020-08-05T13:44:34Z</dc:date>
    <item>
      <title>rule with access role that not match</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rule-with-access-role-that-not-match/m-p/93168#M10597</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I've made a rule where the source is an access role containing an Active Directory user, but this rule is never matched.&lt;/P&gt;&lt;P&gt;I've other rules containing access roles that works as expected.&lt;/P&gt;&lt;P&gt;I've also check that pdp knows about this user with the command&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;pdp monitor user user_name&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;and the user is known to pdp.&lt;/FONT&gt;&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Is there a way to understand why the rule does not match?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks in advance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2020 14:39:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rule-with-access-role-that-not-match/m-p/93168#M10597</guid>
      <dc:creator>Paolo_Francese</dc:creator>
      <dc:date>2020-08-03T14:39:53Z</dc:date>
    </item>
    <item>
      <title>Re: rule with access role that not match</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rule-with-access-role-that-not-match/m-p/93409#M10598</link>
      <description>&lt;P&gt;There are some version / hotfix level specific issues of this nature in earlier releases, quickest path will be to seek help from TAC to investigate &amp;amp; correlate with any known issues vs config etc.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2020 12:09:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rule-with-access-role-that-not-match/m-p/93409#M10598</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2020-08-05T12:09:00Z</dc:date>
    </item>
    <item>
      <title>Re: rule with access role that not match</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rule-with-access-role-that-not-match/m-p/93413#M10599</link>
      <description>&lt;P&gt;I better investigate this issue and I discovered that identity is get from an Identity Collector that send username and IP to the gateways, but between the user and the gateways there is a router that NAT the connections, so the traffic generated by the user reaches the gateway with a source IP that is not the one reported by Identity Collector.&lt;/P&gt;&lt;P&gt;I think that the rule mismatch is caused because of this IP mismatch due to NAT.&lt;BR /&gt;What do you think?&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2020 12:53:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rule-with-access-role-that-not-match/m-p/93413#M10599</guid>
      <dc:creator>Paolo_Francese</dc:creator>
      <dc:date>2020-08-05T12:53:43Z</dc:date>
    </item>
    <item>
      <title>Re: rule with access role that not match</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rule-with-access-role-that-not-match/m-p/93427#M10600</link>
      <description>&lt;P&gt;Can be the case&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2020 13:44:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rule-with-access-role-that-not-match/m-p/93427#M10600</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-08-05T13:44:34Z</dc:date>
    </item>
    <item>
      <title>Re: rule with access role that not match</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rule-with-access-role-that-not-match/m-p/93638#M10601</link>
      <description>&lt;P&gt;How does the access role looks like? If it's for a specific user/group from AD and ANY machines, the only needed info is the username, so I'm not so sure that NAT is causing the problem.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Aug 2020 12:33:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rule-with-access-role-that-not-match/m-p/93638#M10601</guid>
      <dc:creator>MartinTzvetanov</dc:creator>
      <dc:date>2020-08-07T12:33:07Z</dc:date>
    </item>
    <item>
      <title>Re: rule with access role that not match</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rule-with-access-role-that-not-match/m-p/93647#M10602</link>
      <description>&lt;P&gt;Access role object is populated only with one active directory user, other field are set to default values.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Aug 2020 13:33:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rule-with-access-role-that-not-match/m-p/93647#M10602</guid>
      <dc:creator>Paolo_Francese</dc:creator>
      <dc:date>2020-08-07T13:33:25Z</dc:date>
    </item>
  </channel>
</rss>

