<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Associating specific accessrole groups with specific vpn authentication in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Associating-specific-accessrole-groups-with-specific-vpn/m-p/104848#M8293</link>
    <description>&lt;P&gt;You can certainly allow for different authentication methods as shown in the screenshot provided.&lt;BR /&gt;You can also provide access control based on different LDAP groups these users are in.&lt;BR /&gt;What does associating the LDAP group with a specific authentication method achieve exactly?&lt;/P&gt;</description>
    <pubDate>Wed, 09 Dec 2020 22:22:55 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-12-09T22:22:55Z</dc:date>
    <item>
      <title>Associating specific accessrole groups with specific vpn authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Associating-specific-accessrole-groups-with-specific-vpn/m-p/104719#M8283</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I really hope someone can tell me easy way to do this. For example, in Cisco or Fortigate, you can assign specific vpn groups to use authentication you want (say radius, aaa and so on), but on Check Point, I dont know whats best way of doing it, as customer does NOT want to change setting on authentication for vpn on gateway cluster to specific method. What they want to do is this:&lt;/P&gt;&lt;P&gt;Say they have accessrule group called citrix-users ONLY for citrix users and they want to associate that group with radius auth&lt;/P&gt;&lt;P&gt;then they may have tacasc accessrole and they want to associate it with tacacs auth when connecting to vpn site&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Possible? I spoke to TAC about it and they did not sound confident at all how this is even supposed to work. we went through setting up user template and then creating ldap group to associate certain AD groups to it, but then its still not clear how to tie that into proper auth...its not clear at all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If anyone has any insight, I would really appreciate it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tx!!&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 03:18:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Associating-specific-accessrole-groups-with-specific-vpn/m-p/104719#M8283</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2020-12-09T03:18:13Z</dc:date>
    </item>
    <item>
      <title>Re: Associating specific accessrole groups with specific vpn authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Associating-specific-accessrole-groups-with-specific-vpn/m-p/104724#M8285</link>
      <description>&lt;P&gt;You should be able assign different users different forms of authentication…if users are locally defined.&lt;BR /&gt;Not sure how you can mix authentication schemes otherwise.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 04:34:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Associating-specific-accessrole-groups-with-specific-vpn/m-p/104724#M8285</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-09T04:34:45Z</dc:date>
    </item>
    <item>
      <title>Re: Associating specific accessrole groups with specific vpn authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Associating-specific-accessrole-groups-with-specific-vpn/m-p/104837#M8290</link>
      <description>&lt;P&gt;Hey Dameon,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thats not at all what customer wants...ok attached a screenshot of it in here. Actually what they would like is to have specific AD groups associated with specific authentication schemes and on gateway vpn auth tab, that does not even seems to be an option. I spoke to Tier 3 guy in dallas, but he does not seem to know if thats dosble and said would check with esc team. Screenshot attached. So how to associate groups with auth?? These are NOT local users, but AD ones.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 19:50:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Associating-specific-accessrole-groups-with-specific-vpn/m-p/104837#M8290</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2020-12-09T19:50:50Z</dc:date>
    </item>
    <item>
      <title>Re: Associating specific accessrole groups with specific vpn authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Associating-specific-accessrole-groups-with-specific-vpn/m-p/104841#M8291</link>
      <description>&lt;P&gt;You can define different authentication schemes but I’m pretty sure if the same username exists in, say, RADIUS and TACACS, there is no way to differentiate between the two.&lt;BR /&gt;The group resolution is usually done independently of the authentication (at least that’s how it works with Identity Awareness).&lt;BR /&gt;Sounds like an RFE to me.&lt;BR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 20:48:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Associating-specific-accessrole-groups-with-specific-vpn/m-p/104841#M8291</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-09T20:48:08Z</dc:date>
    </item>
    <item>
      <title>Re: Associating specific accessrole groups with specific vpn authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Associating-specific-accessrole-groups-with-specific-vpn/m-p/104843#M8292</link>
      <description>&lt;P&gt;Well, they would all be different groups on AD and no user would belong to 2 same groups, so its pretty shocking there would be no way on CP to do this...on Fortigate and Cisco is super easy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 21:00:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Associating-specific-accessrole-groups-with-specific-vpn/m-p/104843#M8292</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2020-12-09T21:00:07Z</dc:date>
    </item>
    <item>
      <title>Re: Associating specific accessrole groups with specific vpn authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Associating-specific-accessrole-groups-with-specific-vpn/m-p/104848#M8293</link>
      <description>&lt;P&gt;You can certainly allow for different authentication methods as shown in the screenshot provided.&lt;BR /&gt;You can also provide access control based on different LDAP groups these users are in.&lt;BR /&gt;What does associating the LDAP group with a specific authentication method achieve exactly?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 22:22:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Associating-specific-accessrole-groups-with-specific-vpn/m-p/104848#M8293</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-09T22:22:55Z</dc:date>
    </item>
    <item>
      <title>Re: Associating specific accessrole groups with specific vpn authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Associating-specific-accessrole-groups-with-specific-vpn/m-p/104849#M8294</link>
      <description>&lt;P&gt;What it achieves is that thats how they have it with Cisco and they dont wish to change it...they ONLY want certain groups of users say use radius auth and there are some groups where username/password is enough. When I spoke with TAC today, yes, we discussed the gateway auth option from screenshot I gave in my last response, but even there, there is no option anywhere to select specific group that can be tied to certain auth type. Last night, we did end up creating user template, which lets you add user group, which then can contain ldap group, that can be added to accessrole object...BUT, that still does not let us tie it to any type of auth on the gateway, very frustrating.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway, tac guy said will check with escalations and let us know tomorrow. We may try set up another ldap group and test with different ad branch. Weird thing is, even for radius, you log in with username and password, but then when radius part comes in, it never shows proper options on the vpn client...&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 22:33:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Associating-specific-accessrole-groups-with-specific-vpn/m-p/104849#M8294</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2020-12-09T22:33:54Z</dc:date>
    </item>
    <item>
      <title>Re: Associating specific accessrole groups with specific vpn authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Associating-specific-accessrole-groups-with-specific-vpn/m-p/104851#M8295</link>
      <description>&lt;P&gt;So...what's the end user experience on Cisco like with this?&lt;BR /&gt;Do they have to choose an authentication method on the client side?&lt;BR /&gt;What happens if they pick the "wrong" option (or is that even possible to do)?&lt;/P&gt;
&lt;P&gt;The more you can tell about what the expected user experience and the WHY behind said experience (beyond "Cisco does it and they don't want to change") the better.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 22:51:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Associating-specific-accessrole-groups-with-specific-vpn/m-p/104851#M8295</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-09T22:51:38Z</dc:date>
    </item>
    <item>
      <title>Re: Associating specific accessrole groups with specific vpn authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Associating-specific-accessrole-groups-with-specific-vpn/m-p/104853#M8296</link>
      <description>&lt;P&gt;Ok, I will explain...so you create user group, assign whatever AD users you want, associate auth method with that group, save config and thats it. Once rules are in place for vpn, users will be prompted to authenticate based on the method assigned...clear?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 23:04:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Associating-specific-accessrole-groups-with-specific-vpn/m-p/104853#M8296</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2020-12-09T23:04:33Z</dc:date>
    </item>
    <item>
      <title>Re: Associating specific accessrole groups with specific vpn authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Associating-specific-accessrole-groups-with-specific-vpn/m-p/104867#M8297</link>
      <description>&lt;P&gt;That only tells me how to configure it as an admin, not what an end user experiences when they try and log in.&lt;/P&gt;
&lt;P&gt;When you define an LDAP AU, you can specify what authentication methods are allowed for all users under that AU.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-12-09 at 6.58.45 PM.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/9622i25DE159E23BF2611/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2020-12-09 at 6.58.45 PM.png" alt="Screen Shot 2020-12-09 at 6.58.45 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I'm guessing you could create several AUs against the same LDAP servers with specific branches for each group you're interested in.&lt;BR /&gt;Each AU would specify different authentication schemes that could be used.&amp;nbsp;&lt;BR /&gt;Not quite sure what the end user experience would be here, though.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't know for sure, but I suspect this is an RFE.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 03:06:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Associating-specific-accessrole-groups-with-specific-vpn/m-p/104867#M8297</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-10T03:06:55Z</dc:date>
    </item>
    <item>
      <title>Re: Associating specific accessrole groups with specific vpn authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Associating-specific-accessrole-groups-with-specific-vpn/m-p/104868#M8298</link>
      <description>&lt;P&gt;Yea...funny enough, that option you showed does not do anything, sadly. Thats default setting and usually all those options are allowed anyway, so no need to change them. Really, what end users currently experience is they only have to choose auth method once on Cisco anyconnect (equal to CP vpn endpoint client) and thats it, no need to mess around after. Tac guy from Dallas said he will consult with escalation, because Im positive there is a way to do this on CP...EVERY major fw vendor has this ability and its so easy to do it.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 03:11:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Associating-specific-accessrole-groups-with-specific-vpn/m-p/104868#M8298</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2020-12-10T03:11:28Z</dc:date>
    </item>
    <item>
      <title>Re: Associating specific accessrole groups with specific vpn authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Associating-specific-accessrole-groups-with-specific-vpn/m-p/104871#M8299</link>
      <description>&lt;P&gt;The multiple authentication schemes dialog you showed earlier does make those authentication options available to the end user after you push policy.&lt;BR /&gt;However, there is no way to tie a specific authentication method to a user group.&lt;BR /&gt;If the ID is unique in LDAP and associated with that specific group, they'll have access regardless of how they authenticated.&lt;BR /&gt;If you want to provide different levels of access based on how they authenticate instead of or in addition to the LDAP group, pretty sure that is an RFE.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 03:19:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Associating-specific-accessrole-groups-with-specific-vpn/m-p/104871#M8299</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-10T03:19:47Z</dc:date>
    </item>
    <item>
      <title>Re: Associating specific accessrole groups with specific vpn authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Associating-specific-accessrole-groups-with-specific-vpn/m-p/104873#M8300</link>
      <description>&lt;P&gt;If thats the case, I find that really surprising, if not shocking. If you take Cisco asa, super easy. fortigate (same thing), even palo alto has this ability and its very straight forward. Though, I will say we did make progress today and I may ask the customer tomorrow to try create another user template that includes specific ldap group (that can be created to reference specific AD group) and then add it to accessrole group and we will test more. Even tac said that seems to be the best way...so lets keep our fingers crossed &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 03:25:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Associating-specific-accessrole-groups-with-specific-vpn/m-p/104873#M8300</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2020-12-10T03:25:06Z</dc:date>
    </item>
    <item>
      <title>Re: Associating specific accessrole groups with specific vpn authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Associating-specific-accessrole-groups-with-specific-vpn/m-p/104874#M8301</link>
      <description>&lt;P&gt;That does sound promising, keep me posted.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 03:32:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Associating-specific-accessrole-groups-with-specific-vpn/m-p/104874#M8301</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-10T03:32:05Z</dc:date>
    </item>
    <item>
      <title>Re: Associating specific accessrole groups with specific vpn authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Associating-specific-accessrole-groups-with-specific-vpn/m-p/104877#M8302</link>
      <description>&lt;P&gt;You bet brother : ). In IT community, its important to share knowledge, regardless what vendor it is.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 03:46:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Associating-specific-accessrole-groups-with-specific-vpn/m-p/104877#M8302</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2020-12-10T03:46:44Z</dc:date>
    </item>
    <item>
      <title>Re: Associating specific accessrole groups with specific vpn authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Associating-specific-accessrole-groups-with-specific-vpn/m-p/104883#M8303</link>
      <description>&lt;P&gt;You can make a pretty decent career out of sharing information &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 04:31:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Associating-specific-accessrole-groups-with-specific-vpn/m-p/104883#M8303</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-10T04:31:02Z</dc:date>
    </item>
    <item>
      <title>Re: Associating specific accessrole groups with specific vpn authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Associating-specific-accessrole-groups-with-specific-vpn/m-p/104884#M8304</link>
      <description>&lt;P&gt;Of course &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 04:31:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Associating-specific-accessrole-groups-with-specific-vpn/m-p/104884#M8304</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2020-12-10T04:31:46Z</dc:date>
    </item>
  </channel>
</rss>

