<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remote Access Endpoint VPN policy is not matching the rule in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-Endpoint-VPN-policy-is-not-matching-the-rule/m-p/136874#M20705</link>
    <description>&lt;P&gt;Thanks I need to verify that. let me revert with my findings then.&lt;/P&gt;</description>
    <pubDate>Tue, 21 Dec 2021 03:49:01 GMT</pubDate>
    <dc:creator>Blason_R</dc:creator>
    <dc:date>2021-12-21T03:49:01Z</dc:date>
    <item>
      <title>Remote Access Endpoint VPN policy is not matching the rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-Endpoint-VPN-policy-is-not-matching-the-rule/m-p/136489#M20629</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have R80.30 firewalls and R80.40 mgmt server. It has been upgraded from R77.30 almost a year back and now I would like to enable Application and URL filtering blade on policy hence activated the same from Manage policy and layers.&lt;/P&gt;&lt;P&gt;However since I have Remote access Endpoint client based VPN rules setup in legacy mode like this&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;I am unable to do so and while installing policy it throws error. Then I tried converting legacy user access to access role however users are successfully getting authenticated but they are unable to connect as per policy and traffic is getting dropped on clean up rule. So I disabled Rule#9 and enabled Rule #8; however traffic is getting dropped any reason why?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HelpDeskAccessRole.JPG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14583i4B9ACC35D7BCAF00/image-size/medium?v=v2&amp;amp;px=400" role="button" title="HelpDeskAccessRole.JPG" alt="HelpDeskAccessRole.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AccessRole.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14585i1077FF1C908664CB/image-size/large?v=v2&amp;amp;px=999" role="button" title="AccessRole.JPG" alt="AccessRole.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am I missing anything here?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Dec 2021 03:41:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-Endpoint-VPN-policy-is-not-matching-the-rule/m-p/136489#M20629</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2021-12-16T03:41:51Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access Endpoint VPN policy is not matching the rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-Endpoint-VPN-policy-is-not-matching-the-rule/m-p/136490#M20630</link>
      <description>&lt;P&gt;Oh! By the way these are local users configured on firewall.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Dec 2021 03:49:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-Endpoint-VPN-policy-is-not-matching-the-rule/m-p/136490#M20630</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2021-12-16T03:49:29Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access Endpoint VPN policy is not matching the rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-Endpoint-VPN-policy-is-not-matching-the-rule/m-p/136599#M20651</link>
      <description>&lt;P&gt;Have you enabled Remote Access as an Identity Source in the gateway?&lt;BR /&gt;It’s not enabled by default.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Dec 2021 06:01:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-Endpoint-VPN-policy-is-not-matching-the-rule/m-p/136599#M20651</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-12-17T06:01:06Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access Endpoint VPN policy is not matching the rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-Endpoint-VPN-policy-is-not-matching-the-rule/m-p/136847#M20694</link>
      <description>&lt;P&gt;Yes this is enabled and I confirmed that. What could be other reason?&lt;/P&gt;</description>
      <pubDate>Mon, 20 Dec 2021 17:34:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-Endpoint-VPN-policy-is-not-matching-the-rule/m-p/136847#M20694</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2021-12-20T17:34:08Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access Endpoint VPN policy is not matching the rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-Endpoint-VPN-policy-is-not-matching-the-rule/m-p/136873#M20704</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I would check that the pdp is associating the AR with the users by running:&lt;/P&gt;
&lt;P&gt;# pdp monitor user &amp;lt;user&amp;gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 711px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14639i46611625756E6388/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I would imagine this would be the cause if the IA settings etc. are correct.&lt;/P&gt;
&lt;P&gt;Here is my user matching a rule correctly based off the AR detected by the pdp:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14640i0CA2F84DC3663345/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14641i342915958D31D2DF/image-size/large?v=v2&amp;amp;px=999" role="button" title="3.png" alt="3.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;If the pdp isn't detecting the AR then you will want to recheck the configuration/debug pdpd to get more info.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Dec 2021 03:45:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-Endpoint-VPN-policy-is-not-matching-the-rule/m-p/136873#M20704</guid>
      <dc:creator>mcatanzaro</dc:creator>
      <dc:date>2021-12-21T03:45:13Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access Endpoint VPN policy is not matching the rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-Endpoint-VPN-policy-is-not-matching-the-rule/m-p/136874#M20705</link>
      <description>&lt;P&gt;Thanks I need to verify that. let me revert with my findings then.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Dec 2021 03:49:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-Endpoint-VPN-policy-is-not-matching-the-rule/m-p/136874#M20705</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2021-12-21T03:49:01Z</dc:date>
    </item>
  </channel>
</rss>

