<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Managment interface - administrator access to GW in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Managment-interface-administrator-access-to-GW/m-p/194520#M36202</link>
    <description>&lt;P&gt;Hello mates,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm looking for a way to create a "trusted clients" list to populate on full Gaia. Kinda like the "Administrator access"&amp;nbsp; in SMB devices. I have FWs on cca 100 diffrent locations. Some od those locations don't have IT staff capable of other tasks than switching cable from one device to new one. So if SIC is successful than great but if not... Need a way to have acces to remote GWs regardless if policy is installed.&lt;/P&gt;&lt;P&gt;Br&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 09 Oct 2023 13:14:14 GMT</pubDate>
    <dc:creator>cir007</dc:creator>
    <dc:date>2023-10-09T13:14:14Z</dc:date>
    <item>
      <title>Managment interface - administrator access to GW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Managment-interface-administrator-access-to-GW/m-p/194520#M36202</link>
      <description>&lt;P&gt;Hello mates,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm looking for a way to create a "trusted clients" list to populate on full Gaia. Kinda like the "Administrator access"&amp;nbsp; in SMB devices. I have FWs on cca 100 diffrent locations. Some od those locations don't have IT staff capable of other tasks than switching cable from one device to new one. So if SIC is successful than great but if not... Need a way to have acces to remote GWs regardless if policy is installed.&lt;/P&gt;&lt;P&gt;Br&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 13:14:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Managment-interface-administrator-access-to-GW/m-p/194520#M36202</guid>
      <dc:creator>cir007</dc:creator>
      <dc:date>2023-10-09T13:14:14Z</dc:date>
    </item>
    <item>
      <title>Re: Administrator access to GW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Managment-interface-administrator-access-to-GW/m-p/194522#M36203</link>
      <description>&lt;P&gt;There is a way to allow WebUI/SSH connectivity to the GW from trusted IPs.&lt;/P&gt;
&lt;P&gt;Go to Gaia WebUI, switch to Advanced view, then go to System Management / Host Access&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-10-09 at 13.19.00.png" style="width: 672px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22713i7F1ACFAC9D6DAC6C/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-10-09 at 13.19.00.png" alt="Screenshot 2023-10-09 at 13.19.00.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Add clients that should be allowed to connect to the GW.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 11:22:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Managment-interface-administrator-access-to-GW/m-p/194522#M36203</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-10-09T11:22:03Z</dc:date>
    </item>
    <item>
      <title>Re: Administrator access to GW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Managment-interface-administrator-access-to-GW/m-p/194524#M36205</link>
      <description>&lt;P&gt;Hey Val,&lt;/P&gt;&lt;P&gt;thank you for prompt replay. Tried this before postig my question, sadly it doesn't work. Meaning security policy is processed, before this list. As we can see from the picture, default is "Any"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Br&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 11:26:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Managment-interface-administrator-access-to-GW/m-p/194524#M36205</guid>
      <dc:creator>cir007</dc:creator>
      <dc:date>2023-10-09T11:26:47Z</dc:date>
    </item>
    <item>
      <title>Re: Administrator access to GW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Managment-interface-administrator-access-to-GW/m-p/194528#M36206</link>
      <description>&lt;P&gt;Partially correct.&lt;/P&gt;
&lt;P&gt;These rules define limited access through the"Management" interface only, regardless of the policy, if you do not disable the implied rules.&lt;/P&gt;
&lt;P&gt;Check if you want to redefine internet facing IF as MANAGEMENT. Lab trials are highly recommended.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 11:59:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Managment-interface-administrator-access-to-GW/m-p/194528#M36206</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-10-09T11:59:20Z</dc:date>
    </item>
    <item>
      <title>Re: Administrator access to GW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Managment-interface-administrator-access-to-GW/m-p/194530#M36207</link>
      <description>&lt;P&gt;What&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;gave you is only thing Ima ware of as well. Otherwise, policy from the management would come into an effect.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 12:09:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Managment-interface-administrator-access-to-GW/m-p/194530#M36207</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-09T12:09:24Z</dc:date>
    </item>
    <item>
      <title>Re: Administrator access to GW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Managment-interface-administrator-access-to-GW/m-p/194540#M36212</link>
      <description>&lt;P&gt;Hm, OK after some testing in lab I came to the following conclusion and questions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- CP admin guides must provide more specific intention of the managment interface and its usage&lt;/P&gt;&lt;P&gt;-meaning GW uses allowed hosts table only when initial policy is loaded, after you install security policy, packet flow to GW is process via policy rules (that was my understaning of the usage of the specific table )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Regardnign impled rules&lt;/EM&gt;- is there an implied rule to process the "allowed hosts" table first? If so could you point me in the right direction.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Check if you want to redefine internet facing IF as MANAGEMENT -&amp;nbsp; &lt;/EM&gt;to my understanding this sould be the case on all WAN only accesible GWs.&amp;nbsp;OR is there any security limitations? After policy is installed and GW object is defined as destination in security policy, GW is accesible via all interfaces.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I guess this solve my problem when connecting a new GW, after that if policy is in order access should work.&lt;/P&gt;&lt;P&gt;Br&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 13:49:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Managment-interface-administrator-access-to-GW/m-p/194540#M36212</guid>
      <dc:creator>cir007</dc:creator>
      <dc:date>2023-10-09T13:49:15Z</dc:date>
    </item>
  </channel>
</rss>

