<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security ID based rules in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-ID-based-rules/m-p/121199#M17239</link>
    <description>&lt;P&gt;It affects how roles are matched.&lt;BR /&gt;If you defined a role based on test.abc.com then rename it to say test2.abc.com, the role will still match because of the SID.&lt;BR /&gt;If you move a user to a different group and that’s how you’ve defined the access role (by group), then the user will be associated with the new role(s) the same as before.&lt;BR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;am I missing something?&lt;/P&gt;</description>
    <pubDate>Mon, 14 Jun 2021 19:56:59 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-06-14T19:56:59Z</dc:date>
    <item>
      <title>Security ID based rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-ID-based-rules/m-p/121194#M17237</link>
      <description>&lt;P&gt;R81 Enhancement:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Security ID (SID) support for Identity Awareness - Move users and groups to different LDAP Organizational Units without the need to modify the Access Role Policy.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;We can enable SID on the gateway.&lt;/P&gt;&lt;P&gt;How to use create a policy for this ?&lt;/P&gt;&lt;P&gt;For Example:There are two OU's 'test.abc.com' and 'test1.abc.com'&lt;/P&gt;&lt;P&gt;test.abc.com OU has access to facebook as this is marketing unit.&lt;/P&gt;&lt;P&gt;test1.abc.com has access to financial sites.&lt;/P&gt;&lt;P&gt;User1 belongs to 'test.abc.com' and user2 belongs to 'test1.abc.com'&lt;/P&gt;&lt;P&gt;I have&amp;nbsp; created the access role for the user1 to allow facebook.&lt;/P&gt;&lt;P&gt;When I user moves from 'test.abc.com' to 'test1.abc.com', how user1 will have access to Financial sites as the access role is still matches to a policy for 'facebook'&lt;/P&gt;&lt;P&gt;Is there anything which I am missing ?&lt;/P&gt;&lt;P&gt;Is there any white paper released for this ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jun 2021 18:52:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-ID-based-rules/m-p/121194#M17237</guid>
      <dc:creator>Nagaraja</dc:creator>
      <dc:date>2021-06-14T18:52:24Z</dc:date>
    </item>
    <item>
      <title>Re: Security ID based rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-ID-based-rules/m-p/121199#M17239</link>
      <description>&lt;P&gt;It affects how roles are matched.&lt;BR /&gt;If you defined a role based on test.abc.com then rename it to say test2.abc.com, the role will still match because of the SID.&lt;BR /&gt;If you move a user to a different group and that’s how you’ve defined the access role (by group), then the user will be associated with the new role(s) the same as before.&lt;BR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;am I missing something?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jun 2021 19:56:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-ID-based-rules/m-p/121199#M17239</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-06-14T19:56:59Z</dc:date>
    </item>
    <item>
      <title>Re: Security ID based rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-ID-based-rules/m-p/141055#M21721</link>
      <description>&lt;P&gt;Hello community, Any experience with this LDAP_SID feature in production environments?&lt;BR /&gt;The configuration does not look too mature to me. Any plans to implement this more resilient in the Configuration database?&lt;/P&gt;&lt;P&gt;KR, Peter&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Feb 2022 16:57:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-ID-based-rules/m-p/141055#M21721</guid>
      <dc:creator>Peter_Thome</dc:creator>
      <dc:date>2022-02-09T16:57:34Z</dc:date>
    </item>
  </channel>
</rss>

