<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity awareness Access Rules in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-Access-Rules/m-p/74425#M11621</link>
    <description>What does the Access Role you’ve configured look like?</description>
    <pubDate>Fri, 07 Feb 2020 11:25:08 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-02-07T11:25:08Z</dc:date>
    <item>
      <title>Identity awareness Access Rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-Access-Rules/m-p/74402#M11620</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;We are using&amp;nbsp;&lt;SPAN&gt;Identity awareness with identity collector. When we create a access rule within the access policy in order to block a group of computers from accessing the internet, however this does not work, the traffic doesnt even match this rule.&amp;nbsp;&lt;/SPAN&gt;Creating a simular rule for users from the AD works just fine but not the computers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;Running version R80.20 HFA Take 91&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;//Johan&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 08:54:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-Access-Rules/m-p/74402#M11620</guid>
      <dc:creator>Johan_Rudberg</dc:creator>
      <dc:date>2020-02-07T08:54:37Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness Access Rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-Access-Rules/m-p/74425#M11621</link>
      <description>What does the Access Role you’ve configured look like?</description>
      <pubDate>Fri, 07 Feb 2020 11:25:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-Access-Rules/m-p/74425#M11621</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-02-07T11:25:08Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness Access Rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-Access-Rules/m-p/74439#M11622</link>
      <description>&lt;P&gt;probably there is no match for this access role. When you select specific workstations, which setting you have for "users" section?&lt;/P&gt;&lt;P&gt;Is your workstation exist here?&lt;/P&gt;&lt;P&gt;pep s u q mchn &amp;lt;workstation_name&amp;gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 12:43:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-Access-Rules/m-p/74439#M11622</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2020-02-07T12:43:18Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness Access Rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-Access-Rules/m-p/74448#M11623</link>
      <description>&lt;P&gt;Are the computers you are trying to block part of the AD domain? or are they standalone?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 13:19:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-Access-Rules/m-p/74448#M11623</guid>
      <dc:creator>Daniel_Taney</dc:creator>
      <dc:date>2020-02-07T13:19:32Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness Access Rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-Access-Rules/m-p/74465#M11624</link>
      <description>&lt;P&gt;I remember I had to split "mixed"roles after upgrade to R80.x as machine IDs stopped working if the same role also had user IDs.&lt;/P&gt;
&lt;P&gt;Try using role that has machine IDs / groups only if you have not done that&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 15:19:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-Access-Rules/m-p/74465#M11624</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2020-02-07T15:19:16Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness Access Rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-Access-Rules/m-p/74970#M11625</link>
      <description>&lt;P&gt;We resolved this problem by rebooting the management server, now the rule works!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However from the moment when a computer is added to the AD group it takes X hours before the rule deny the traffic, why is that so?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;//Johan&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2020 12:27:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-Access-Rules/m-p/74970#M11625</guid>
      <dc:creator>Johan_Rudberg</dc:creator>
      <dc:date>2020-02-12T12:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness Access Rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-Access-Rules/m-p/74972#M11626</link>
      <description>&lt;P&gt;By default it is 4 hours. You have to change it if you want more frequent active directory fetch for group membership. You can do manually by using following command:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;pdp update&lt;/P&gt;&lt;P&gt;Command: root-&amp;gt;update&lt;/P&gt;&lt;P&gt;Available options:&lt;BR /&gt;all - recalculate all users and machines group membership&lt;BR /&gt;specific - recalculate group membership for a user/machine&lt;BR /&gt;refetch_interval - LDAP user info refetch interval&lt;BR /&gt;update_rate - the max number of sessions updated within a minute&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2020 12:35:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-Access-Rules/m-p/74972#M11626</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2020-02-12T12:35:41Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness Access Rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-Access-Rules/m-p/75071#M11627</link>
      <description>It is a AD Group configured under Machine in the Access Role</description>
      <pubDate>Thu, 13 Feb 2020 08:34:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-Access-Rules/m-p/75071#M11627</guid>
      <dc:creator>Johan_Rudberg</dc:creator>
      <dc:date>2020-02-13T08:34:36Z</dc:date>
    </item>
  </channel>
</rss>

