<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Rules containing an Access Role which is a group containing a user from another AD does not matc in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rules-containing-an-Access-Role-which-is-a-group-containing-a/m-p/145404#M22904</link>
    <description>&lt;P&gt;Thanks for your answer,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;So even if the user is in the group, the rule won't match because they are not created on the same AD domain ?&amp;nbsp;&lt;BR /&gt;There is no other solution to counter this than creating Access Roles containing both users/groups of A and B ?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 04 Apr 2022 15:32:54 GMT</pubDate>
    <dc:creator>clement_leconte</dc:creator>
    <dc:date>2022-04-04T15:32:54Z</dc:date>
    <item>
      <title>Rules containing an Access Role which is a group containing a user from another AD does not match</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rules-containing-an-Access-Role-which-is-a-group-containing-a/m-p/145111#M22674</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;Hello everyone,&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I didn't found the location for Identity Awareness issues, therefore I picked General Topics but if anyone knows what is the right location please let me know,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The title is a bit long and maybe will not be clear enough so here's my case :&amp;nbsp;&lt;/P&gt;&lt;P&gt;First the architecture :&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I have one checkpoint Gateway (4400) on&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;standalone configuration&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;with the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;R80.40&lt;/STRONG&gt;&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;release&lt;/LI&gt;&lt;LI&gt;I have 2 Active Directories (let's say&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;A&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;B&lt;/STRONG&gt;) which are on different VLANs (respectively&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;1&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;2&lt;/STRONG&gt;) which are on a trust relationship (I can log on a computer being in domain&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;A&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;with an account of domain&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;B&lt;/STRONG&gt;)&lt;/LI&gt;&lt;LI&gt;I have one computer which is in VLAN&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;1&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and registered in domain&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;B&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The main purpose of this architecture is to test Identity Awareness and its abilities,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've decided to use the terminal agents (light version) and managed to make kerberos logging in for both domain, I've set up rules to test both users from&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;A&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;B&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and everything is fine so far.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But when I've tried to create a rule with an&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Access Role&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;containing a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;local group created on A&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;that is containing&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;users of B&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;users of B&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;aren't matched on the rule while&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;users of A&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;that are in the same local group are matched by the rule,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Actually we won't have the access on&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;B&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to create and manage groups, I know that we can do the same thing by creating an Access Role on the SmartConsole and adding the groups / users to it and it should be working fine but this will be tedious as all groups/OU... are already created on&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;A&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Is there anything that I can do to fix this or am I missing something ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know that it may not be clear so feel free to ask any question you have,&lt;/P&gt;&lt;P&gt;Thanks in advance for your help and your time,&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 31 Mar 2022 09:05:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rules-containing-an-Access-Role-which-is-a-group-containing-a/m-p/145111#M22674</guid>
      <dc:creator>clement_leconte</dc:creator>
      <dc:date>2022-03-31T09:05:54Z</dc:date>
    </item>
    <item>
      <title>Re: Rules containing an Access Role which is a group containing a user from another AD does not matc</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rules-containing-an-Access-Role-which-is-a-group-containing-a/m-p/145402#M22902</link>
      <description>&lt;P&gt;The group information for a user is only obtained by querying the relevant AD domain via LDAP.&lt;BR /&gt;Since you're not querying the users of B (and only A), the users from B won't be part of the relevant group.&lt;BR /&gt;This seems like expected behavior.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 15:25:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rules-containing-an-Access-Role-which-is-a-group-containing-a/m-p/145402#M22902</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-04-04T15:25:33Z</dc:date>
    </item>
    <item>
      <title>Re: Rules containing an Access Role which is a group containing a user from another AD does not matc</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rules-containing-an-Access-Role-which-is-a-group-containing-a/m-p/145404#M22904</link>
      <description>&lt;P&gt;Thanks for your answer,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;So even if the user is in the group, the rule won't match because they are not created on the same AD domain ?&amp;nbsp;&lt;BR /&gt;There is no other solution to counter this than creating Access Roles containing both users/groups of A and B ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 15:32:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rules-containing-an-Access-Role-which-is-a-group-containing-a/m-p/145404#M22904</guid>
      <dc:creator>clement_leconte</dc:creator>
      <dc:date>2022-04-04T15:32:54Z</dc:date>
    </item>
    <item>
      <title>Re: Rules containing an Access Role which is a group containing a user from another AD does not matc</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rules-containing-an-Access-Role-which-is-a-group-containing-a/m-p/145419#M22909</link>
      <description>&lt;P&gt;Right, because the underlying LDAP query is likely only getting the users from the domain in which it is queried, not the ones from the cross-trust relationship.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 16:58:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rules-containing-an-Access-Role-which-is-a-group-containing-a/m-p/145419#M22909</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-04-04T16:58:20Z</dc:date>
    </item>
  </channel>
</rss>

