<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to Create IA Access Role with Multi Src,Dst IP-Address? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-Create-IA-Access-Role-with-Multi-Src-Dst-IP-Address/m-p/91396#M6981</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have planned to integrate Identity Awareness for Large Scale with existing production firewall, we have existing 1700+ Rule with "networks, service object" So my target is Add "AD User, Networks, Service object on the top of existing rule with new rule for Monitoring before migrate to New Rule with Access role.&lt;/P&gt;&lt;P&gt;Example Existing Rule&lt;/P&gt;&lt;P&gt;Source IP have 20+ Object, Destination IP 20+ Object&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If possible don't change behavior for my customer admin to manage their firewall. existing behavior admin can verify src,dst IP its just look at the rule because src,dst shown on the rule. In the feature admin have to double click on "access-role" for check src,dst IP some thing like that.&amp;nbsp;&lt;/P&gt;&lt;P&gt;My English skill is not so good, But I'm try to explain!&lt;/P&gt;&lt;P&gt;GIAG R80.30&lt;/P&gt;</description>
    <pubDate>Tue, 14 Jul 2020 05:37:28 GMT</pubDate>
    <dc:creator>Security_Consul</dc:creator>
    <dc:date>2020-07-14T05:37:28Z</dc:date>
    <item>
      <title>How to Create IA Access Role with Multi Src,Dst IP-Address?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-Create-IA-Access-Role-with-Multi-Src-Dst-IP-Address/m-p/91396#M6981</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have planned to integrate Identity Awareness for Large Scale with existing production firewall, we have existing 1700+ Rule with "networks, service object" So my target is Add "AD User, Networks, Service object on the top of existing rule with new rule for Monitoring before migrate to New Rule with Access role.&lt;/P&gt;&lt;P&gt;Example Existing Rule&lt;/P&gt;&lt;P&gt;Source IP have 20+ Object, Destination IP 20+ Object&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If possible don't change behavior for my customer admin to manage their firewall. existing behavior admin can verify src,dst IP its just look at the rule because src,dst shown on the rule. In the feature admin have to double click on "access-role" for check src,dst IP some thing like that.&amp;nbsp;&lt;/P&gt;&lt;P&gt;My English skill is not so good, But I'm try to explain!&lt;/P&gt;&lt;P&gt;GIAG R80.30&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 05:37:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-Create-IA-Access-Role-with-Multi-Src-Dst-IP-Address/m-p/91396#M6981</guid>
      <dc:creator>Security_Consul</dc:creator>
      <dc:date>2020-07-14T05:37:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to Create IA Access Role with Multi Src,Dst IP-Address?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-Create-IA-Access-Role-with-Multi-Src-Dst-IP-Address/m-p/91504#M6990</link>
      <description>&lt;P&gt;An Access Role can incorporate one or more of the following:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Username&lt;/LI&gt;
&lt;LI&gt;Host (as registered to Active Directory)&lt;/LI&gt;
&lt;LI&gt;Specific Source IP or Network&lt;/LI&gt;
&lt;LI&gt;Remote Access Client (from R80.10)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Access Roles can be used in a Source or Destination in a role.&lt;BR /&gt;However, you can't mix "regular" network objects and Access Roles in the same source/destination cell, discussed here: &lt;A href="https://community.checkpoint.com/t5/Policy-Management/Policy-verification-failed-for-rule-with-network-objects-and/m-p/66718#M3942" target="_blank"&gt;https://community.checkpoint.com/t5/Policy-Management/Policy-verification-failed-for-rule-with-network-objects-and/m-p/66718#M3942&lt;/A&gt;&lt;BR /&gt;This might mean duplicating some of your existing rules.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 15:43:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-Create-IA-Access-Role-with-Multi-Src-Dst-IP-Address/m-p/91504#M6990</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-07-14T15:43:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to Create IA Access Role with Multi Src,Dst IP-Address?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-Create-IA-Access-Role-with-Multi-Src-Dst-IP-Address/m-p/91580#M6997</link>
      <description>&lt;P&gt;Its only way to create access role rule just add everything need to consider of the rule into 1 access role object (Network Object, AD User)&amp;nbsp;&lt;/P&gt;&lt;P&gt;May be add more one access role object&amp;nbsp;&lt;/P&gt;&lt;P&gt;But my target no need to change admin's behavior.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2020 07:01:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-Create-IA-Access-Role-with-Multi-Src-Dst-IP-Address/m-p/91580#M6997</guid>
      <dc:creator>Security_Consul</dc:creator>
      <dc:date>2020-07-15T07:01:20Z</dc:date>
    </item>
  </channel>
</rss>

