<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ipassignment.conf and LDAP grop in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ipassignment-conf-and-LDAP-grop/m-p/227940#M43831</link>
    <description>&lt;P&gt;It's user/password authentication, right?&lt;BR /&gt;What if you put it in as it is in AD (i.e. with a Capital)?&lt;BR /&gt;If this doesn't work, suggest involving TAC.&lt;/P&gt;</description>
    <pubDate>Wed, 25 Sep 2024 17:34:53 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-09-25T17:34:53Z</dc:date>
    <item>
      <title>ipassignment.conf and LDAP grop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ipassignment-conf-and-LDAP-grop/m-p/202255#M38065</link>
      <description>&lt;P&gt;Hello again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Continuation of a previous post but the old post is marked as resolved (because it was) to allow contributor to receive credit.&amp;nbsp;&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In a nutshell - we need to limit access to a network host to a small group of 5 individuals.&amp;nbsp; The solution has to work with NAT (Identity Awareness is out as it doesn't work with NAT).&amp;nbsp; This solution will be used for WFH users - the current OM IP pool is Nat'd to the internal interface of the Check Point.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;My solution:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I'd like to configure the ipassignment.conf file to assign a range of IPs to my already existing AD group - then limit access to the resource based on the static IPs. (This will be used for WFH users).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;What I've done:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Created a draft of my ipassignment.conf file&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is how my ipassignment.conf file will look referencing SK:&amp;nbsp;&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk33422" target="_self"&gt;sk33422&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;#Gateway&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Type&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;IP Address&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User Name&lt;/P&gt;&lt;P&gt;==================================================&lt;/P&gt;&lt;P&gt;IP of gateway&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; range&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 10.0.0.0-10.0.0.5&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Test Group&amp;nbsp; (AD group)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Created an LDAP Account Unit that points directly to my AD group - so the UID is my group.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Trying to create an LDAP Group Object that the ipassignment.conf file can reference.&amp;nbsp; The Group's scope is the first option - "All Account-Unit's Users"&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Questions:&lt;/STRONG&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Unfortunately, my AD security group contains a space in the name.&amp;nbsp; When I try and create the LDAP group, I'm receiving the error "Object name contains space..."&amp;nbsp;&amp;nbsp;How can I get around this?&amp;nbsp;&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Will this plan work?&amp;nbsp;&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":face_with_rolling_eyes:"&gt;🙄&lt;/span&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you, and as always - any help is always much appreciated!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Joe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2024 22:29:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ipassignment-conf-and-LDAP-grop/m-p/202255#M38065</guid>
      <dc:creator>Joe_Kanaszka</dc:creator>
      <dc:date>2024-01-04T22:29:54Z</dc:date>
    </item>
    <item>
      <title>Re: ipassignment.conf and LDAP grop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ipassignment-conf-and-LDAP-grop/m-p/202259#M38066</link>
      <description>&lt;P&gt;Even if you could get past the UI validation in SmartConsole, I suspect that space will be problematic in ipassignment.conf as well.&lt;BR /&gt;Change the name to something without a space.&lt;BR /&gt;Otherwise, this should work.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2024 22:42:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ipassignment-conf-and-LDAP-grop/m-p/202259#M38066</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-01-04T22:42:52Z</dc:date>
    </item>
    <item>
      <title>Re: ipassignment.conf and LDAP grop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ipassignment-conf-and-LDAP-grop/m-p/202262#M38067</link>
      <description>&lt;P&gt;Ok cool. Thank you! &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2024 23:09:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ipassignment-conf-and-LDAP-grop/m-p/202262#M38067</guid>
      <dc:creator>Joe_Kanaszka</dc:creator>
      <dc:date>2024-01-04T23:09:10Z</dc:date>
    </item>
    <item>
      <title>Re: ipassignment.conf and LDAP grop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ipassignment-conf-and-LDAP-grop/m-p/227698#M43797</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;we have configured the file for an LDAP user but the user is not receiving the ip.&lt;/P&gt;&lt;P&gt;as you can see on both screenshots, we pushed the file on both gateways of the cluster&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2024 08:11:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ipassignment-conf-and-LDAP-grop/m-p/227698#M43797</guid>
      <dc:creator>DAKad</dc:creator>
      <dc:date>2024-09-24T08:11:29Z</dc:date>
    </item>
    <item>
      <title>Re: ipassignment.conf and LDAP grop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ipassignment-conf-and-LDAP-grop/m-p/227930#M43828</link>
      <description>&lt;P&gt;Please refer to&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk33422" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk33422&lt;/A&gt;&amp;nbsp;for what exactly to use based on how the user authenticates.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2024 17:08:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ipassignment-conf-and-LDAP-grop/m-p/227930#M43828</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-09-25T17:08:36Z</dc:date>
    </item>
    <item>
      <title>Re: ipassignment.conf and LDAP grop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ipassignment-conf-and-LDAP-grop/m-p/227934#M43830</link>
      <description>&lt;P&gt;Hello PhoneBoy,&lt;/P&gt;&lt;P&gt;see the screenshot of the line added at the end of the file.&lt;/P&gt;&lt;P&gt;user log to the vpn through LDAP with the AD account , his name is on capital letter from active directory but when he wants to connecte on the VPN client, he use small letter like i wrote on the file and it works but still taking the ip from the pool instead of the ipassignment file&lt;/P&gt;&lt;P&gt;Also after checking with vpn ipafile_check $FWDIR/conf/ipassignment.con detail , i get the&amp;nbsp; output on the second screenshot&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2024 17:22:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ipassignment-conf-and-LDAP-grop/m-p/227934#M43830</guid>
      <dc:creator>DAKad</dc:creator>
      <dc:date>2024-09-25T17:22:19Z</dc:date>
    </item>
    <item>
      <title>Re: ipassignment.conf and LDAP grop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ipassignment-conf-and-LDAP-grop/m-p/227940#M43831</link>
      <description>&lt;P&gt;It's user/password authentication, right?&lt;BR /&gt;What if you put it in as it is in AD (i.e. with a Capital)?&lt;BR /&gt;If this doesn't work, suggest involving TAC.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2024 17:34:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ipassignment-conf-and-LDAP-grop/m-p/227940#M43831</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-09-25T17:34:53Z</dc:date>
    </item>
  </channel>
</rss>

