<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: rule based on a group not working anymore in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rule-based-on-a-group-not-working-anymore/m-p/233690#M45230</link>
    <description>&lt;P&gt;So in SmartLog I see the correct group in one gateway but not all. In CLI on the gateway that would require the correct info running&amp;nbsp;pep s u q usr username returns User Groups:&amp;lt;Unavailable&amp;gt;. We're using Identity Collector. In the Identity Collector gui everything looks fine&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 25 Nov 2024 15:06:11 GMT</pubDate>
    <dc:creator>flachance</dc:creator>
    <dc:date>2024-11-25T15:06:11Z</dc:date>
    <item>
      <title>rule based on a group not working anymore</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rule-based-on-a-group-not-working-anymore/m-p/233688#M45229</link>
      <description>&lt;P&gt;The management and gateways are R81.20 JHF take 76&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We made two rules for application access similar to this&lt;/P&gt;
&lt;P&gt;1.access_role_exception to Facebook Allow&lt;/P&gt;
&lt;P&gt;2.access_role_blockFB to Facebook Drop&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;access_role_exceptions contains AD group FB_exception&lt;/P&gt;
&lt;P&gt;access_role_blockFB contains AD group Org_group&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Everybody is in Org_group and some are also in FB_exception&lt;/P&gt;
&lt;P&gt;This worked well as of last Friday. This morning everybody is blocked even if they are in FB_exception.&lt;/P&gt;
&lt;P&gt;I can see in the logs that the correct groups are associated with the correct users.&lt;/P&gt;
&lt;P&gt;What could cause this? Why won't it match rule 1 anymore?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;
&lt;P&gt;Francis&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 14:58:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rule-based-on-a-group-not-working-anymore/m-p/233688#M45229</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2024-11-25T14:58:15Z</dc:date>
    </item>
    <item>
      <title>Re: rule based on a group not working anymore</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rule-based-on-a-group-not-working-anymore/m-p/233690#M45230</link>
      <description>&lt;P&gt;So in SmartLog I see the correct group in one gateway but not all. In CLI on the gateway that would require the correct info running&amp;nbsp;pep s u q usr username returns User Groups:&amp;lt;Unavailable&amp;gt;. We're using Identity Collector. In the Identity Collector gui everything looks fine&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 15:06:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rule-based-on-a-group-not-working-anymore/m-p/233690#M45230</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2024-11-25T15:06:11Z</dc:date>
    </item>
    <item>
      <title>Re: rule based on a group not working anymore</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rule-based-on-a-group-not-working-anymore/m-p/233704#M45233</link>
      <description>&lt;P&gt;If problem is only present on one gateway. I don’t think there is an issue on IDC or AD. Worth running basic health check like hcp maybe some important daemon is crashed like pdp or pep. If it is a cluster maybe do failover and reboot.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 16:14:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rule-based-on-a-group-not-working-anymore/m-p/233704#M45233</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-11-25T16:14:15Z</dc:date>
    </item>
    <item>
      <title>Re: rule based on a group not working anymore</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rule-based-on-a-group-not-working-anymore/m-p/233713#M45234</link>
      <description>&lt;P&gt;so for one user I tried pdp update specific username and it updated is Identity Roles properly.&lt;/P&gt;
&lt;P&gt;I have another one with the issue when I do a pep s u q user username for him I see two entries (two different IPs) the oldest one has the correct Identity Roles but the newest one doesn't.&lt;/P&gt;
&lt;P&gt;I also tried pdp update specific username for him but it changed nothing&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 18:06:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rule-based-on-a-group-not-working-anymore/m-p/233713#M45234</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2024-11-25T18:06:41Z</dc:date>
    </item>
    <item>
      <title>Re: rule based on a group not working anymore</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rule-based-on-a-group-not-working-anymore/m-p/233714#M45235</link>
      <description>&lt;P&gt;I tried pdp update specific machinename for him and it's ok now.&lt;/P&gt;
&lt;P&gt;I'm not sure I understand how often this should update on its own.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 18:10:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rule-based-on-a-group-not-working-anymore/m-p/233714#M45235</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2024-11-25T18:10:14Z</dc:date>
    </item>
    <item>
      <title>Re: rule based on a group not working anymore</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rule-based-on-a-group-not-working-anymore/m-p/233731#M45246</link>
      <description>&lt;P&gt;I would try test like this...instead of access role group, use subnet in the rule and see if it works by an IP. If it does, then you know 100% without any doubt its role association thats the issue.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2024 01:37:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rule-based-on-a-group-not-working-anymore/m-p/233731#M45246</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-26T01:37:45Z</dc:date>
    </item>
  </channel>
</rss>

