<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity awareness access group problem in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-access-group-problem/m-p/57858#M12616</link>
    <description>&lt;P&gt;The access role we are using only has one specific AD group assigned, and for some reason this access roles stopped working.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I did check IA via smartlog the way you described it and for this particular user, and when i correlate it with the access logs, i see a lot of Access Roles updates where it seems like the user sometimes is not part of the needed Access Role anymore.&lt;/P&gt;&lt;P&gt;Those were probably the moments i was playing with the config.&lt;/P&gt;&lt;P&gt;As a test, I created a new AD group, not nested with other permission groups but it only had 2 users in it.&lt;BR /&gt;When adding this new test group to a new test Access Role i created, the rule worked perfectly and the user could access the needed recources.&lt;/P&gt;&lt;P&gt;That leads me to believe there is only a problem for with a specific nested AD group, and it's only for this specific policy rule using the troublesome Access Role.&lt;BR /&gt;We use a lot of other Access Roles with nested AD groups and without issues.&lt;/P&gt;&lt;P&gt;I wonder how to get this working again. I'm puzzled.&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jul 2019 08:01:49 GMT</pubDate>
    <dc:creator>Dave</dc:creator>
    <dc:date>2019-07-10T08:01:49Z</dc:date>
    <item>
      <title>Identity awareness access group problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-access-group-problem/m-p/57791#M12611</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have Identity Awareness implemented for a lot of stuff, but it seems now that it got broken for one specific access rule.&lt;/P&gt;&lt;P&gt;RDP access to certain servers is controlled via IA and the access role is configured with a specific AD group, for which users in this group have access.&lt;/P&gt;&lt;P&gt;All of the sudden, it stopped working and users cannot RDP to these servers anymore.&lt;/P&gt;&lt;P&gt;Weird thing is that it was perfectly working before.&lt;/P&gt;&lt;P&gt;When basic troubleshooting this and removing the group access but adding the users separately, this works again and RDP is working fine again.&lt;/P&gt;&lt;P&gt;I'm fairly new to Checkpoint firewalls so any guidance how to pinpoint what the exact problem is would be highly appreciated.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2019 10:19:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-access-group-problem/m-p/57791#M12611</guid>
      <dc:creator>Dave</dc:creator>
      <dc:date>2019-07-09T10:19:37Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness access group problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-access-group-problem/m-p/57830#M12612</link>
      <description>You could try to remove publish and again add the group into the access role and publish and install.</description>
      <pubDate>Tue, 09 Jul 2019 20:29:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-access-group-problem/m-p/57830#M12612</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-07-09T20:29:16Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness access group problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-access-group-problem/m-p/57835#M12613</link>
      <description>&lt;P&gt;Hi Dave,&lt;/P&gt;&lt;P&gt;To assist you fully, could you provide the following information please:&lt;/P&gt;&lt;P&gt;1) What is the version of your management server and that of your gateway?&lt;/P&gt;&lt;P&gt;2) What is the time stamp of when the issue first occurred?&lt;/P&gt;&lt;P&gt;3) What is the identity acquisition method used?&lt;/P&gt;&lt;P&gt;4) How many domain controllers does the gateway communicate with?&lt;/P&gt;&lt;P&gt;Thanks Dave.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2019 22:15:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-access-group-problem/m-p/57835#M12613</guid>
      <dc:creator>Nick_Doropoulos</dc:creator>
      <dc:date>2019-07-09T22:15:10Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness access group problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-access-group-problem/m-p/57845#M12614</link>
      <description>&lt;P&gt;Hi Nick,&lt;/P&gt;&lt;P&gt;1) mgmt and gateway are both running on R80.20&lt;/P&gt;&lt;P&gt;2)first occurence 4th of July&lt;/P&gt;&lt;P&gt;3)policy rule with access role used, where a nested AD group needs to be consulted, but only 2 deep and actual users are member of 3 different groups&lt;BR /&gt;Access role group name -&amp;gt; specific group added to grant access -&amp;gt; AD group&lt;/P&gt;&lt;P&gt;We got 4 DC but i'm not sure if all are used to communicate with the gateways.&lt;/P&gt;&lt;P&gt;Strange thing is that we have a bunch of other similar access roles set up also which do still work, only with this particular one we have a problem.&lt;BR /&gt;Also when i remove the AD group from the access role and add just the specific users, it just works....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps, as i said, i'm fairly new into the game&lt;/P&gt;&lt;P&gt;Thanks a lot!&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2019 06:36:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-access-group-problem/m-p/57845#M12614</guid>
      <dc:creator>Dave</dc:creator>
      <dc:date>2019-07-10T06:36:33Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness access group problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-access-group-problem/m-p/57847#M12615</link>
      <description>&lt;P&gt;You can always do basic checks that user/IP is actually assicoated with the role.&lt;/P&gt;
&lt;P&gt;You can do it in both - SmartLog (use filter blade:"Identity Awareness" and IP / uername then look for log-in type event and see what role is associated with the user) or expert CLI&lt;/P&gt;
&lt;P&gt;pep s u q cid x.x.x.x&lt;/P&gt;
&lt;P&gt;pep s u q usr USERNAME&lt;/P&gt;
&lt;P&gt;We had small issue after upgrade to R80.10 (from R77.30) - roles that had used both usernames and machine ID's in the same role stopped working, so we had to create two seperate roles - one for machine IDs and one for usernames&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2019 07:09:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-access-group-problem/m-p/57847#M12615</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2019-07-10T07:09:08Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness access group problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-access-group-problem/m-p/57858#M12616</link>
      <description>&lt;P&gt;The access role we are using only has one specific AD group assigned, and for some reason this access roles stopped working.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I did check IA via smartlog the way you described it and for this particular user, and when i correlate it with the access logs, i see a lot of Access Roles updates where it seems like the user sometimes is not part of the needed Access Role anymore.&lt;/P&gt;&lt;P&gt;Those were probably the moments i was playing with the config.&lt;/P&gt;&lt;P&gt;As a test, I created a new AD group, not nested with other permission groups but it only had 2 users in it.&lt;BR /&gt;When adding this new test group to a new test Access Role i created, the rule worked perfectly and the user could access the needed recources.&lt;/P&gt;&lt;P&gt;That leads me to believe there is only a problem for with a specific nested AD group, and it's only for this specific policy rule using the troublesome Access Role.&lt;BR /&gt;We use a lot of other Access Roles with nested AD groups and without issues.&lt;/P&gt;&lt;P&gt;I wonder how to get this working again. I'm puzzled.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2019 08:01:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-access-group-problem/m-p/57858#M12616</guid>
      <dc:creator>Dave</dc:creator>
      <dc:date>2019-07-10T08:01:49Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness access group problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-access-group-problem/m-p/57928#M12617</link>
      <description>&lt;P&gt;Did the DN of the problematic group get changed in AD?&amp;nbsp; Perhaps renamed or nested under a different OU?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2019 15:30:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-access-group-problem/m-p/57928#M12617</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-07-10T15:30:29Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness access group problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-access-group-problem/m-p/57930#M12618</link>
      <description>you can check how deep gateway will dig using this command below&lt;BR /&gt;&lt;BR /&gt;pdp nested status&lt;BR /&gt;Enabled - recursive. Depth: 20&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 10 Jul 2019 15:47:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-access-group-problem/m-p/57930#M12618</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2019-07-10T15:47:02Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness access group problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-access-group-problem/m-p/57932#M12619</link>
      <description>Additionally check this SK&lt;BR /&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk128212" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk128212&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 10 Jul 2019 15:49:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-access-group-problem/m-p/57932#M12619</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2019-07-10T15:49:56Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness access group problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-access-group-problem/m-p/58451#M12620</link>
      <description>&lt;P&gt;To come back to this, it was a problem in R80.20 for which a hotfix needed to be installed in order to get a whole bunch of other stuff resolved as well.&lt;/P&gt;&lt;P&gt;With the &lt;STRONG&gt;R80.20 Jumbo HotFix -&amp;nbsp;General Availability&amp;nbsp;Take 87&lt;/STRONG&gt; installed, nested AD groups don't pose any problem no more ... for now &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2019 08:23:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-access-group-problem/m-p/58451#M12620</guid>
      <dc:creator>Dave</dc:creator>
      <dc:date>2019-07-18T08:23:08Z</dc:date>
    </item>
  </channel>
</rss>

