<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Awareness - R81.20 For Lab in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/216449#M41245</link>
    <description>&lt;P&gt;Yes, i have capture on Wireshark about API packet sent to Checkpoint,&amp;nbsp;ClearPass is not enclosing the ip-address parameter in outgoing communications, thus the current issue lies with ClearPass. I have opened a case with Aruba TAC and hope they can assist me in resolving this issue. Additionally, I would like to inquire about licenses for the lab. Where can I obtain a temporary license, as my current lab setup will run out of its license in a few days?&lt;/P&gt;</description>
    <pubDate>Wed, 05 Jun 2024 02:55:04 GMT</pubDate>
    <dc:creator>HaTM</dc:creator>
    <dc:date>2024-06-05T02:55:04Z</dc:date>
    <item>
      <title>Identity Awareness - R81.20 For Lab</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/215049#M41225</link>
      <description>&lt;P&gt;I setup a virtual lab with Checkpoint Firewall Security Management and Standalone R81.20 to test the integration of the Aruba ClearPass Policy Manager solution. When I enabled the Identity Awareness feature on Checkpoint and tried to post an API to the Firewall address, there was no response. Therefore, I tried using Postman and a browser to the Firewall's API address, but both showed a&amp;nbsp; 404 Error "No URL" result as shown below:&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;lt;!DOCTYPE&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;HTML&amp;nbsp;PUBLIC&amp;nbsp;"-//W3C//DTD&amp;nbsp;HTML&amp;nbsp;4.0&amp;nbsp;Transitional//EN"&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN&gt;HTML&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN&gt;HEAD&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN&gt;TITLE&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;404&amp;nbsp;File&amp;nbsp;Not&amp;nbsp;Found&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN&gt;TITLE&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN&gt;HEAD&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN&gt;BODY&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;The&amp;nbsp;URL&amp;nbsp;you&amp;nbsp;requested&amp;nbsp;could&amp;nbsp;not&amp;nbsp;be&amp;nbsp;found&amp;nbsp;on&amp;nbsp;this&amp;nbsp;server.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;So i really need help to resolve this issue, tks!&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 23 May 2024 02:01:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/215049#M41225</guid>
      <dc:creator>HaTM</dc:creator>
      <dc:date>2024-05-23T02:01:15Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - R81.20 For Lab</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/215135#M41226</link>
      <description>&lt;P&gt;What precise steps were taken to enable Identity Awareness on the gateway?&lt;BR /&gt;At the very least you need to enable the blade and push policy to the relevant gateway.&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 20:40:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/215135#M41226</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-05-23T20:40:31Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - R81.20 For Lab</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/215152#M41227</link>
      <description>&lt;P&gt;Hi, tks for your responsed&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have reinstalled the lab and successfully sent API using Postman. Currently, I am encountering issues sending API from ClearPass Policy Manager to the Firewall. I have configured the Context Server actions on ClearPass and tested by logging in/out users from CP OnGuard Agent; however, I do not see any Identity Awareness logs on Check Point. How can I troubleshoot the log sending/receiving between these two servers? I would greatly appreciate your guidance.&lt;/P&gt;</description>
      <pubDate>Fri, 24 May 2024 01:39:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/215152#M41227</guid>
      <dc:creator>HaTM</dc:creator>
      <dc:date>2024-05-24T01:39:59Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - R81.20 For Lab</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/215193#M41228</link>
      <description>&lt;P&gt;I'm not familiar with the integration with Aruba.&lt;BR /&gt;Generally speaking, though:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Users should be communicated to our gateways via the IDA API&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Groups (necessary for Access Roles) will come from LDAP (usually from on-premise Active Directory)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;I'd start by checking the Aruba side of this to make sure it is sending us information.&lt;BR /&gt;A simple tcpdump should verify the Aruba server is sending traffic to the gateway on port 443.&lt;/P&gt;</description>
      <pubDate>Fri, 24 May 2024 14:49:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/215193#M41228</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-05-24T14:49:37Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - R81.20 For Lab</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/215262#M41229</link>
      <description>&lt;P&gt;Thank you for your response. I have currently opened a support case with Aruba TAC to debug why the API is not being sent from ClearPass. I have an additional question: with this integration, does CheckPoint require user authentication (via LDAP or AD)? Can I create a dynamic policy to manage user access on CheckPoint based solely on parameters such as IP address and the ClearPass PC health check results?&lt;/P&gt;</description>
      <pubDate>Mon, 27 May 2024 01:50:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/215262#M41229</guid>
      <dc:creator>HaTM</dc:creator>
      <dc:date>2024-05-27T01:50:27Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - R81.20 For Lab</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/215395#M41230</link>
      <description>&lt;P&gt;Identity Awareness receives information&amp;nbsp;via Identity Agents, Identity Collector, or the Identity Awareness API (e.g. for Aruba Clearpass).&lt;BR /&gt;Among this information is the user...which is not strictly required.&lt;BR /&gt;However, one or more Identity Tags would probably need to be defined to create the relevant Access Policy rules.&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2024 16:15:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/215395#M41230</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-05-28T16:15:51Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - R81.20 For Lab</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/216142#M41231</link>
      <description>&lt;P&gt;Hi, i tried to post API to Firewall IA API via Postman with this content:&amp;nbsp;&lt;/P&gt;&lt;P&gt;{"shared-secret":"**********", "user": "NACAdmin","ip-address":"1.2.3.4","identity-source": "Aruba ClearPass Policy Manager","calculate-roles":0,"fetch-user-groups": 0,"fetch-machine-groups": 0,"roles": "[%{Role Test}]"}&lt;/P&gt;&lt;P&gt;But i got result:&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"message"&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"Unexpected&amp;nbsp;type&amp;nbsp;'string'&amp;nbsp;for&amp;nbsp;parameter&amp;nbsp;'roles'&amp;nbsp;in&amp;nbsp;object&amp;nbsp;of&amp;nbsp;type&amp;nbsp;'add-identity'.&amp;nbsp;Type&amp;nbsp;should&amp;nbsp;be&amp;nbsp;convertible&amp;nbsp;to&amp;nbsp;array"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;So how can i push roles of user to Firewall ? cus at Checkpoint's guide here&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/latest/IdentityAPIs/#web/add-identity~v1%20" target="_blank"&gt;https://sc1.checkpoint.com/documents/latest/IdentityAPIs/#web/add-identity~v1%20&lt;/A&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;i can send role name to CP.&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 03 Jun 2024 02:36:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/216142#M41231</guid>
      <dc:creator>HaTM</dc:creator>
      <dc:date>2024-06-03T02:36:50Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - R81.20 For Lab</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/216230#M41232</link>
      <description>&lt;P&gt;Roles needs to be an array, which are enclosed in square brackets.&lt;BR /&gt;The roles listed between the square brackets must be enclosed in quotes (i.e. strings).&lt;BR /&gt;Your JSON should look like this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;{
  "shared-secret": "**********",
  "user": "NACAdmin",
  "ip-address": "1.2.3.4",
  "identity-source": "Aruba ClearPass Policy Manager",
  "calculate-roles": 0,
  "fetch-user-groups": 0,
  "fetch-machine-groups": 0,
  "roles": ["Role Test"]
}&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 13:36:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/216230#M41232</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-06-03T13:36:30Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - R81.20 For Lab</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/216314#M41237</link>
      <description>&lt;P&gt;Hi Phone Boy, Thank for your reply.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have successfully sent a manual API and the Checkpoint Firewall has added identity for the User. Currently, I am having an issue with ClearPass sending the API automatically to Checkpoint. Through capturing packets with Wireshark at the Firewall, I observed that there was a POST message sent from ClearPass.&amp;nbsp; However, there is no record in the log blade:IA. What should I do to debug this case, please help me&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2024 08:20:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/216314#M41237</guid>
      <dc:creator>HaTM</dc:creator>
      <dc:date>2024-06-04T08:20:37Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - R81.20 For Lab</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/216427#M41242</link>
      <description>&lt;P&gt;Can you see the exact API call with JSON body sent by Clearpass to the gateway?&lt;BR /&gt;Without that, and given that you were able to make a successful API call on your own, I assume this issue is on the Clearpass side.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2024 18:27:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/216427#M41242</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-06-04T18:27:57Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - R81.20 For Lab</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/216449#M41245</link>
      <description>&lt;P&gt;Yes, i have capture on Wireshark about API packet sent to Checkpoint,&amp;nbsp;ClearPass is not enclosing the ip-address parameter in outgoing communications, thus the current issue lies with ClearPass. I have opened a case with Aruba TAC and hope they can assist me in resolving this issue. Additionally, I would like to inquire about licenses for the lab. Where can I obtain a temporary license, as my current lab setup will run out of its license in a few days?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 02:55:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/216449#M41245</guid>
      <dc:creator>HaTM</dc:creator>
      <dc:date>2024-06-05T02:55:04Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - R81.20 For Lab</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/216607#M41273</link>
      <description>&lt;P&gt;You can generate evaluation licenses via UserCenter, as described here:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Topics/How-to-Request-an-Evaluation-License-for-Security-Gateways-and/m-p/40391#M8499" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/How-to-Request-an-Evaluation-License-for-Security-Gateways-and/m-p/40391#M8499&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 23:44:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/216607#M41273</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-06-05T23:44:24Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - R81.20 For Lab</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/218445#M41700</link>
      <description>&lt;P&gt;Hi, kindly answer my one more question. When i turn-up Identity Awareness on Firewall and use AD Query option.&amp;nbsp;To connect the Firewall to the AD/LDAP server, I see there is a note that an Administrator account must be used. So, what is the admin account here? What are its privileges (e.g., domain admin, schema admin, or some other admin)? Do you have any documentation about this that you can share?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 454px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26396i8CE6A530AF91EE2D/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2024 07:48:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/218445#M41700</guid>
      <dc:creator>HaTM</dc:creator>
      <dc:date>2024-06-24T07:48:16Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - R81.20 For Lab</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/218518#M41713</link>
      <description>&lt;P&gt;Start here:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk93938" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk93938&lt;/A&gt;&lt;BR /&gt;If you don't like users being part of the "Server Operators" group, see also:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk104900" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk104900&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;In general, we recommend using Identity Collector over ADQuery:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk60301" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk60301&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2024 16:32:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/218518#M41713</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-06-24T16:32:09Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - R81.20 For Lab</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/218593#M41727</link>
      <description>&lt;P&gt;To integrate Firewall Checkpoint with an OpenLDAP server, what level of user permissions do I need to create at the LDAP end for the Firewall to be able to use the AD Query feature? Kindly guide me, tks!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2024 09:00:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/218593#M41727</guid>
      <dc:creator>HaTM</dc:creator>
      <dc:date>2024-06-25T09:00:05Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - R81.20 For Lab</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/218643#M41744</link>
      <description>&lt;P&gt;ADQuery uses WMI, which I'm fairly certain OpenLDAP does not implement.&lt;BR /&gt;In any case, we don't support the use of OpenLDAP for Identity Awareness.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2024 15:27:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/218643#M41744</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-06-25T15:27:42Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - R81.20 For Lab</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/219829#M42030</link>
      <description>&lt;P&gt;Hi PhoneBoy,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have successfully sent an API from ClearPass to Checkpoint. However, now I have a new issue with updating the Access Role on the Firewall. For every Role value that I send with the variable "calculate-roles" = 1, the Firewall automatically updates all my users into all the existing Access Roles on the Firewall.&lt;/P&gt;&lt;DIV class=""&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-07-06_16-49-28.png" style="width: 795px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26636iA3340D5648D96C4B/image-size/large?v=v2&amp;amp;px=999" role="button" title="2024-07-06_16-49-28.png" alt="2024-07-06_16-49-28.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;P&gt;How can I update the role for the user correctly on the firewall? Please guide me, thank you.&lt;/P&gt;</description>
      <pubDate>Sat, 06 Jul 2024 09:51:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/219829#M42030</guid>
      <dc:creator>HaTM</dc:creator>
      <dc:date>2024-07-06T09:51:12Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - R81.20 For Lab</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/219997#M42087</link>
      <description>&lt;P&gt;To use groups sent through the Identity Awareness API, they have to be created as Identity Tags using the same capitalization as defined on the source.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_IdentityAwareness_AdminGuide/Content/Topics-IDAG/Configuring-Identity-Awareness-Using-Identity-Tags-in-Access-Role-Matching.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_IdentityAwareness_AdminGuide/Content/Topics-IDAG/Configuring-Identity-Awareness-Using-Identity-Tags-in-Access-Role-Matching.htm&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2024 18:47:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/219997#M42087</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-08T18:47:14Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - R81.20 For Lab</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/220129#M42116</link>
      <description>&lt;P&gt;Hi PhoneBoy,&amp;nbsp;&lt;BR /&gt;My config for Access Role with Specified network below:&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Subnet added: 10.84.3.0/24" style="width: 611px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26671i4177E140CB10419B/image-size/large?v=v2&amp;amp;px=999" role="button" title="Access Role ANSV 1.PNG" alt="Subnet added: 10.84.3.0/24" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Subnet added: 10.84.3.0/24&lt;/span&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;Subnet added: 10.84.3.0/24&lt;/DIV&gt;&lt;DIV class=""&gt;when user login successfully, i only see the successful login logs follow:&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Log details 1.PNG" style="width: 783px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26672iBB9A3F067EFEBE74/image-size/large?v=v2&amp;amp;px=999" role="button" title="Log details 1.PNG" alt="Log details 1.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="User login successfully 1.PNG" style="width: 945px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26673i6AFAAF3315378337/image-size/large?v=v2&amp;amp;px=999" role="button" title="User login successfully 1.PNG" alt="User login successfully 1.PNG" /&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;P&gt;So I'm confused whether without the Access Role Up log, whether this User of mine can be correctly mapped to that CPPM Access Role or not?&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2024 16:42:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/220129#M42116</guid>
      <dc:creator>HaTM</dc:creator>
      <dc:date>2024-07-09T16:42:48Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - R81.20 For Lab</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/220138#M42119</link>
      <description>&lt;P&gt;The log you provided shows the roles that were mapped to the user (in your example CPPM).&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2024 17:56:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-R81-20-For-Lab/m-p/220138#M42119</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-09T17:56:25Z</dc:date>
    </item>
  </channel>
</rss>

