<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Access Role not working? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-not-working/m-p/144660#M22541</link>
    <description>&lt;P&gt;Thanks Andy.&amp;nbsp; I take a bit of comfort in the knowledge I'm not doing anything completely obviously wrong at this stage?!&lt;/P&gt;</description>
    <pubDate>Thu, 24 Mar 2022 12:05:56 GMT</pubDate>
    <dc:creator>biskit</dc:creator>
    <dc:date>2022-03-24T12:05:56Z</dc:date>
    <item>
      <title>Access Role not working?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-not-working/m-p/144456#M22486</link>
      <description>&lt;P&gt;I suspect I'm missing something obvious, so I'm after some help please.&lt;/P&gt;&lt;P&gt;I've set up remote access using Azure AD auth (Identity Provider) - both for Mobile Access (with SNX) and client VPN.&amp;nbsp; Both authenticate fine and I get an Office Mode IP.&amp;nbsp; Great.&lt;/P&gt;&lt;P&gt;I've configured an Access Role where I've specified certain users from Azure AD.&amp;nbsp; When I click "add" it browses Azure AD with no problem, and I select the users I want.&lt;/P&gt;&lt;P&gt;The Access Role is in a rule allowing access to the LAN.&lt;/P&gt;&lt;P&gt;But it doesn't work.&amp;nbsp; It's as if nothing is being picked up on that Access Role rule.&amp;nbsp; Traffic is dropped on the cleanup.&lt;/P&gt;&lt;P&gt;If I add a rule lower down to allow the Office Mode net to get to the LAN, then my traffic works on that rule.&lt;/P&gt;&lt;P&gt;I can't work out why my traffic isn't allowed on the Access Role rule which has my Azure name in it?&amp;nbsp; &amp;nbsp;Obviously I don't want to leave the Office Mode rule in otherwise I have no way of creating rules based on the person.&amp;nbsp; I presumed Access Roles should do this but they are being completely ignored &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I've tried with and without Remote Access in the VPN column, and also tried with Captive Portal in the Accept column.&amp;nbsp; No difference...&lt;/P&gt;&lt;P&gt;Does anyone have any ideas please?!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 18:09:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-not-working/m-p/144456#M22486</guid>
      <dc:creator>biskit</dc:creator>
      <dc:date>2022-03-22T18:09:37Z</dc:date>
    </item>
    <item>
      <title>Re: Access Role not working?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-not-working/m-p/144469#M22490</link>
      <description>&lt;P&gt;Hey Matt,&lt;/P&gt;
&lt;P&gt;Interesting issue for sure...I have experience with access roles, as I constantly work with customer who uses identity awareness. Here is some basics I would check...so, when it does not work, say if username is (for argument's sake) john123. If you ran command on the firewall pdp monitor user john123...do you see anything at all? If not, what happens is you run pdp update all and try after 30 seconds or so?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In case you still dont see anything, are there any logs at all on that rule since you created it?&lt;/P&gt;
&lt;P&gt;What do you see if you run adlog a dc command?&lt;/P&gt;
&lt;P&gt;I have some time Thursday, happy to do remote session and see if we can fix this for you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 23:46:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-not-working/m-p/144469#M22490</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-03-22T23:46:38Z</dc:date>
    </item>
    <item>
      <title>Re: Access Role not working?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-not-working/m-p/144472#M22493</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;On the gateway object, identity awareness tab, is "Remote Access" option checked on the list of Identity Sources? after the vpn client connects to the gateway, check if the firewall has any identity related to that IP "pdp monitor ip X.X.X.X" or "pep show user all | grep X.X.X.X"&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2022 00:00:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-not-working/m-p/144472#M22493</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2022-03-23T00:00:27Z</dc:date>
    </item>
    <item>
      <title>Re: Access Role not working?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-not-working/m-p/144473#M22494</link>
      <description>&lt;P&gt;Forgot that part about remote access, good point.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2022 00:23:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-not-working/m-p/144473#M22494</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-03-23T00:23:18Z</dc:date>
    </item>
    <item>
      <title>Re: Access Role not working?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-not-working/m-p/144653#M22538</link>
      <description>&lt;P&gt;I've done some more testing following installation of T38 and I've noticed the following behaviour.&lt;/P&gt;&lt;P&gt;When my access role is set to &lt;STRONG&gt;Users &lt;/STRONG&gt;&amp;gt; &lt;STRONG&gt;All Identified Users&lt;/STRONG&gt;, then my client traffic to the LAN&amp;nbsp;&lt;STRONG&gt;works&lt;/STRONG&gt; via the correct Access Role rule number, and I see the following on the gateway:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[Expert@xxxxxxxx:0]# pdp monitor user matt.dunn@xxxxxxxx.co.uk
Session: 8874a8a4
Session UUID: {A496290D-51C6-D19F-FA8A-CCA85A19F050}
Ip: 192.168.51.4
Users:  
 Matt.Dunn@xxxxxxxx.co.uk {ecc188a5}
  LogUsername: Matt.Dunn@xxxxxxxxx.co.uk
  Groups: All Users
  Roles: Azure_AD_VPN_Client_Users
  Client Type: Remote Access
  Authentication Method: Trust
  Distinguished Name: 
  Connect Time: Thu Mar 24 09:35:31 2022
  Next Reauthentication: Thu Mar 24 17:36:01 2022
  Next Connectivity Check: -
  Next Ldap Fetch: -
Packet Tagging Status: Not Active
Published Gateways: Local
*****************************************************************&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But, if I set my access role to &lt;STRONG&gt;Users&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Specific Users&lt;/STRONG&gt; then it does &lt;STRONG&gt;not &lt;/STRONG&gt;work, and I get the following on the gateway:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[Expert@xxxxxxxx:0]# pdp monitor user matt.dunn@xxxxxxxx.co.uk
Session: 63d74b8b
Session UUID: {7B3C4106-7A78-07D5-13FA-4E5EFC0322F5}
Ip: 192.168.51.4
Users:  
 Matt.Dunn@xxxxxxxx.co.uk {04a3d0c5}
  LogUsername: Matt.Dunn@xxxxxxxx.co.uk
  Groups: All Users
  Roles: -
  Client Type: Remote Access
  Authentication Method: Trust
  Distinguished Name: 
  Connect Time: Thu Mar 24 10:04:36 2022
  Next Reauthentication: Thu Mar 24 18:05:06 2022
  Next Connectivity Check: -
  Next Ldap Fetch: -
Packet Tagging Status: Not Active
Published Gateways: Local
*****************************************************************&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Notice when I specify users, and I log in as one of the specified users, the gateway no longer detects me as belonging to that access role.&amp;nbsp; The "&lt;STRONG&gt;Roles:-&lt;/STRONG&gt;" line is empty.&lt;/P&gt;&lt;P&gt;When I change back again to &lt;STRONG&gt;All Identified Users&lt;/STRONG&gt; then it works again, the "&lt;STRONG&gt;Roles:-&lt;/STRONG&gt;" line is populated again,&amp;nbsp;and &lt;STRONG&gt;&lt;I&gt;pdp monitor&lt;/I&gt;&lt;/STRONG&gt; shows me in that access role.&lt;/P&gt;&lt;P&gt;So now the issue is - why doesn't it work when I specify usernames in the Access Role?&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2022 10:35:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-not-working/m-p/144653#M22538</guid>
      <dc:creator>biskit</dc:creator>
      <dc:date>2022-03-24T10:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: Access Role not working?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-not-working/m-p/144658#M22539</link>
      <description>&lt;P&gt;I really wish I could give you logical answer, but I dont know at this point. I would do IA debugs and see if we can pin point a reason. I will find the debugs TAC sent me once and send them to you here.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2022 11:48:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-not-working/m-p/144658#M22539</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-03-24T11:48:10Z</dc:date>
    </item>
    <item>
      <title>Re: Access Role not working?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-not-working/m-p/144660#M22541</link>
      <description>&lt;P&gt;Thanks Andy.&amp;nbsp; I take a bit of comfort in the knowledge I'm not doing anything completely obviously wrong at this stage?!&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2022 12:05:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-not-working/m-p/144660#M22541</guid>
      <dc:creator>biskit</dc:creator>
      <dc:date>2022-03-24T12:05:56Z</dc:date>
    </item>
    <item>
      <title>Re: Access Role not working?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-not-working/m-p/144662#M22543</link>
      <description>&lt;P&gt;Do you have time for remote session? I think we spoke once before during COVID, you are in UK if I recall? If so, if you are free at say 2 pm your time, just message me privately and we can do remote...I have some ideas.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2022 12:27:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-not-working/m-p/144662#M22543</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-03-24T12:27:00Z</dc:date>
    </item>
    <item>
      <title>Re: Access Role not working?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-not-working/m-p/145830#M23059</link>
      <description>&lt;P&gt;With some help from TAC I got it working.&amp;nbsp; The current instructions from CP don't quite give the full story, so I've attached some notes to supplement and clarify some steps.&amp;nbsp; The golden rule is - don't miss any steps in SK172909, and don't miss any steps in my attached supplementary notes which fill in some critical gaps in SK172909.&lt;/P&gt;&lt;P&gt;If anyone finds a different/simpler way to achieve this I'd love to know &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2022 16:00:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-not-working/m-p/145830#M23059</guid>
      <dc:creator>biskit</dc:creator>
      <dc:date>2022-04-08T16:00:43Z</dc:date>
    </item>
    <item>
      <title>Re: Access Role not working?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-not-working/m-p/145845#M23073</link>
      <description>&lt;P&gt;Amazing job Matt, thanks for that!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2022 17:24:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-not-working/m-p/145845#M23073</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-04-08T17:24:11Z</dc:date>
    </item>
    <item>
      <title>Re: Access Role not working?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-not-working/m-p/163233#M29126</link>
      <description>&lt;P&gt;Thanks - I needed to follow your AAD instructions to get matches on my AAD Identity Awareness policies. Much appreciated &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2022 22:42:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-not-working/m-p/163233#M29126</guid>
      <dc:creator>AK2</dc:creator>
      <dc:date>2022-11-25T22:42:11Z</dc:date>
    </item>
    <item>
      <title>Re: Access Role not working?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-not-working/m-p/242537#M47108</link>
      <description>&lt;P&gt;Hello biskit&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Detto i'm facing the same issue. But now i'm trying this on my trial Azure AD (Groups is not possible) and using users. Could you please help me with more details.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2025 12:21:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-not-working/m-p/242537#M47108</guid>
      <dc:creator>TRajkumar</dc:creator>
      <dc:date>2025-02-27T12:21:01Z</dc:date>
    </item>
    <item>
      <title>Re: Access Role not working?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-not-working/m-p/243587#M47334</link>
      <description>&lt;P&gt;Hi Biskit&lt;/P&gt;&lt;P&gt;&amp;nbsp; I also facing the same challenge, But in my case i'm using the cloudguard gateways (GCP). I tried the document you have shared but no luck for me. Cloud you please help me to resolve this.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2025 15:08:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Role-not-working/m-p/243587#M47334</guid>
      <dc:creator>TRajkumar</dc:creator>
      <dc:date>2025-03-11T15:08:11Z</dc:date>
    </item>
  </channel>
</rss>

