<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block Rclone executable in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Rclone-executable/m-p/195688#M36474</link>
    <description>&lt;P&gt;You're asking three different questions, only two of them are related to each other.&lt;/P&gt;
&lt;P&gt;Your ability to block rclone on a network device depends entirely on what it accesses.&lt;BR /&gt;I would assume the app just calls the various APIs for AWS/Azure directly.&lt;BR /&gt;Which means: to block this app, you'd need to block access to these services.&lt;BR /&gt;However, that is just a guess and I recommend watching the various logs on the gateway to confirm what it does.&lt;/P&gt;
&lt;P&gt;At this point, there is no monitoring mechanism for Identity Collector.&lt;BR /&gt;I believe this is planned, but if you have specific requirements, reach out to your local office with an RFE request.&lt;/P&gt;
&lt;P&gt;An individual Access Role is an "and" for each of the configurable options (User Group, Machine, Network, RA Client).&lt;BR /&gt;You can create another access role that specifies Machine without the User Group.&lt;BR /&gt;However, some user must log onto the system for a machine identity to be acquired.&lt;/P&gt;</description>
    <pubDate>Thu, 19 Oct 2023 21:00:32 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-10-19T21:00:32Z</dc:date>
    <item>
      <title>Block Rclone executable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Rclone-executable/m-p/195610#M36444</link>
      <description>&lt;P&gt;Hi All,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a question below if someone can answer,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;how to block Rclone (software) executable in checkpoint?&lt;/P&gt;&lt;P&gt;customer having issues with Rclone and wanted to block however the problem is Rclone is command line executable and not an application that can simply block within application control? here is the link if the web&amp;nbsp;&lt;A href="https://rclone.org/" target="_blank"&gt;https://rclone.org/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;is there a way to create an email alert if service on AD is down so the admin can receive when AD is disconnected? customer using Identity Collector.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can access role have both username and machines identity for ID-Awareness and if username not work (AD being disconnected or down) will machine Identity still works?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thansk&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 11:17:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Rclone-executable/m-p/195610#M36444</guid>
      <dc:creator>kamaladmire1</dc:creator>
      <dc:date>2023-10-19T11:17:51Z</dc:date>
    </item>
    <item>
      <title>Re: Block Rclone executable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Rclone-executable/m-p/195619#M36446</link>
      <description>&lt;P&gt;When you say "Block Rclone executable", do you mean on an endpoint? Or do you want to block access to the website?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 11:34:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Rclone-executable/m-p/195619#M36446</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-10-19T11:34:28Z</dc:date>
    </item>
    <item>
      <title>Re: Block Rclone executable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Rclone-executable/m-p/195635#M36452</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;want to block this on firewall level, the issue with this particular one is it access Rclone via repository so not easy to block Web site IP.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 13:23:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Rclone-executable/m-p/195635#M36452</guid>
      <dc:creator>kamaladmire1</dc:creator>
      <dc:date>2023-10-19T13:23:56Z</dc:date>
    </item>
    <item>
      <title>Re: Block Rclone executable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Rclone-executable/m-p/195688#M36474</link>
      <description>&lt;P&gt;You're asking three different questions, only two of them are related to each other.&lt;/P&gt;
&lt;P&gt;Your ability to block rclone on a network device depends entirely on what it accesses.&lt;BR /&gt;I would assume the app just calls the various APIs for AWS/Azure directly.&lt;BR /&gt;Which means: to block this app, you'd need to block access to these services.&lt;BR /&gt;However, that is just a guess and I recommend watching the various logs on the gateway to confirm what it does.&lt;/P&gt;
&lt;P&gt;At this point, there is no monitoring mechanism for Identity Collector.&lt;BR /&gt;I believe this is planned, but if you have specific requirements, reach out to your local office with an RFE request.&lt;/P&gt;
&lt;P&gt;An individual Access Role is an "and" for each of the configurable options (User Group, Machine, Network, RA Client).&lt;BR /&gt;You can create another access role that specifies Machine without the User Group.&lt;BR /&gt;However, some user must log onto the system for a machine identity to be acquired.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 21:00:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Rclone-executable/m-p/195688#M36474</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-10-19T21:00:32Z</dc:date>
    </item>
  </channel>
</rss>

