<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Rule Access Role issue in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Rule-Access-Role-issue/m-p/117695#M16645</link>
    <description>&lt;P&gt;Logins Monitor might be this:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk166076&amp;amp;partition=Basic&amp;amp;product=Identity" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk166076&amp;amp;partition=Basic&amp;amp;product=Identity&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 05 May 2021 04:38:34 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-05-05T04:38:34Z</dc:date>
    <item>
      <title>Identity Rule Access Role issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Rule-Access-Role-issue/m-p/117648#M16632</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have firewall enabled with identity awareness blade. It collects identity from identity collector, which it makes communication to our internal domain controllers for fetching identities and forward to gateway.&lt;/P&gt;&lt;P&gt;We got requirement from user to add specific rule where user can access vendor link from any network (corporate IP only), any user but from particular server.&lt;/P&gt;&lt;P&gt;We created access rule for this requirement. However, its not working. If you suggest any troubleshooting steps, it would be much appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could see traffic getting dropped in firewall when user tries to telnet to vendor portal from the allowed particular server/machine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 May 2021 15:25:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Rule-Access-Role-issue/m-p/117648#M16632</guid>
      <dc:creator>Nandhakumar</dc:creator>
      <dc:date>2021-05-04T15:25:18Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Rule Access Role issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Rule-Access-Role-issue/m-p/117689#M16643</link>
      <description>&lt;P&gt;Let’s start with exactly what you created in the rulebase versus what got logged when the user tried to access.&lt;BR /&gt;Might help to know version/JHF level as well.&lt;BR /&gt;Also maybe check in the CLI of the gateway if it’s associating the right roles using pdp monitor user username.&lt;/P&gt;</description>
      <pubDate>Wed, 05 May 2021 01:59:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Rule-Access-Role-issue/m-p/117689#M16643</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-05-05T01:59:10Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Rule Access Role issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Rule-Access-Role-issue/m-p/117693#M16644</link>
      <description>&lt;P&gt;I have created access role in source column like below&lt;/P&gt;&lt;P&gt;Network - Any&lt;/P&gt;&lt;P&gt;Users - Any&lt;/P&gt;&lt;P&gt;Machine - Specific Security Group created in AD (This group contains machines/servers not any user ID's)&lt;/P&gt;&lt;P&gt;Destination - Vendor Website IP address&lt;/P&gt;&lt;P&gt;Gateway version is R80.40/ JHF Accumulator take 91&lt;/P&gt;&lt;P&gt;When i run pdp monitor user username, I am not getting this access role but getting other access roles. Working fine If I create access role with any network, specific users and any machine (Not for this scenario for others i am saying).&lt;BR /&gt;Why with specific machine is not working?&lt;/P&gt;&lt;P&gt;Also, please let me know how can i make this service in running state and see logs in Login Monitor section of Identity collectors. Please see attached screenshot for details.&lt;/P&gt;</description>
      <pubDate>Wed, 05 May 2021 03:41:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Rule-Access-Role-issue/m-p/117693#M16644</guid>
      <dc:creator>Nandhakumar</dc:creator>
      <dc:date>2021-05-05T03:41:56Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Rule Access Role issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Rule-Access-Role-issue/m-p/117695#M16645</link>
      <description>&lt;P&gt;Logins Monitor might be this:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk166076&amp;amp;partition=Basic&amp;amp;product=Identity" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk166076&amp;amp;partition=Basic&amp;amp;product=Identity&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 May 2021 04:38:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Rule-Access-Role-issue/m-p/117695#M16645</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-05-05T04:38:34Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Rule Access Role issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Rule-Access-Role-issue/m-p/117700#M16647</link>
      <description>&lt;P&gt;We have added Domain Controller as identity source manually but still having same issues. 'Is Forwarded Log Event Collector' was already in disabled state.&amp;nbsp; This &lt;SPAN&gt;sk166076 doesn't&amp;nbsp;&lt;/SPAN&gt;resolve my issue. Do you know that we need to start any windows services for this to work?&lt;/P&gt;</description>
      <pubDate>Wed, 05 May 2021 05:18:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Rule-Access-Role-issue/m-p/117700#M16647</guid>
      <dc:creator>Nandhakumar</dc:creator>
      <dc:date>2021-05-05T05:18:45Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Rule Access Role issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Rule-Access-Role-issue/m-p/117708#M16652</link>
      <description>&lt;P&gt;I don't think I quite understand the requirement here.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you mean that the "vendor link"is a URL and accessed via browser?&lt;/P&gt;
&lt;P&gt;In that case is it safe to assume that the "particular server"is a proxy?&lt;/P&gt;
&lt;P&gt;So users would connect to proxy and proxy would make connection to the vendor?&lt;/P&gt;</description>
      <pubDate>Wed, 05 May 2021 07:00:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Rule-Access-Role-issue/m-p/117708#M16652</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2021-05-05T07:00:09Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Rule Access Role issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Rule-Access-Role-issue/m-p/117716#M16656</link>
      <description>&lt;P&gt;How the users connect to this particular server RDP/SSH? Why don't you just create a rule with this server as IP, not by access role?&lt;/P&gt;</description>
      <pubDate>Wed, 05 May 2021 07:37:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Rule-Access-Role-issue/m-p/117716#M16656</guid>
      <dc:creator>MartinTzvetanov</dc:creator>
      <dc:date>2021-05-05T07:37:16Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Rule Access Role issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Rule-Access-Role-issue/m-p/117765#M16663</link>
      <description>&lt;P&gt;Important is the status in the "Identity Sources" tab, is your configured AD server listed green?&lt;BR /&gt;And if you see a higher number than 0 in column "Total Events Received" you are receiving events &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;On the identity collector you have great log file "&lt;STRONG&gt;C:\Windows\Temp\ia.log&lt;/STRONG&gt;"&lt;/P&gt;&lt;P&gt;To have the events in the UI, you need to &lt;STRONG&gt;turn on the "Loging Monitor"&lt;/STRONG&gt;.&lt;BR /&gt;Please click on the small grey "power button" behind the&amp;nbsp;"Loging Monitor" text and you will see the monitoring events.&lt;BR /&gt;Your screenshot is showing that the "Logins Monitor" is disabled.&lt;/P&gt;&lt;P&gt;By the way i think the question from Martin Tzvetanov is a valid one.&lt;BR /&gt;If any user should have access and you want to allow the system itself as source,&amp;nbsp;&lt;BR /&gt;why not creating a simple rule for allowing "YourServerIP" to vendors Website IP?&lt;BR /&gt;&lt;BR /&gt;But sometimes the destination IP of a website could change,&lt;BR /&gt;so you could think about using FQDN object as destination instead of IP.&lt;/P&gt;</description>
      <pubDate>Wed, 05 May 2021 18:22:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Rule-Access-Role-issue/m-p/117765#M16663</guid>
      <dc:creator>Martin_Stolz</dc:creator>
      <dc:date>2021-05-05T18:22:41Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Rule Access Role issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Rule-Access-Role-issue/m-p/117783#M16664</link>
      <description>&lt;P&gt;Yes we added AD domain controller and tested successfully. All displayed as Green in Identity sources dashboard. Yesterday only i have noticed that power like button for Login Monitor. After I turn on, I could see the event logs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created rule using access role where I given specific machine group as source. In that group, as of now only one server added. In future, group owner may add many servers (&lt;STRONG&gt;That's the reason we haven't created IP base rule&lt;/STRONG&gt;)&lt;/P&gt;&lt;P&gt;I asked user to check but he told that he still unable to telnet for that site. I ran debug on firewall and observed drops.&lt;/P&gt;&lt;P&gt;When I ran this command 'pdp monitor machine &amp;lt;machine name&amp;gt;', I am not getting any output. At this time, 'ignore machine identities' check box was in enabled state in IC.&lt;/P&gt;&lt;P&gt;I disabled 'ignore machine identities' would fix the issue. Now, I want to understand, How long this identity will be seen in gateway?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, how would we force changes made in IC to forward to gateway? I hope, currently it keeps the association time to live for 720 minutes. So if that is case, can't the changes pushed to gateways until it get expire.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 May 2021 03:09:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Rule-Access-Role-issue/m-p/117783#M16664</guid>
      <dc:creator>Nandhakumar</dc:creator>
      <dc:date>2021-05-06T03:09:13Z</dc:date>
    </item>
  </channel>
</rss>

