<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic LDAP group vs Access role objects in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/LDAP-group-vs-Access-role-objects/m-p/110532#M20909</link>
    <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;Could you please point to link where difference between LDAP group and access role is described?&lt;BR /&gt;My issue is:&lt;BR /&gt;We do have used both in our policy (LDAP &amp;amp; AR) objects.&lt;BR /&gt;When user, whose laptop is in domain - meaning internal user with windows - he can match rules setup with access role objects.&lt;BR /&gt;When user, whose laptop isn't in domain, but user is still internal and his account is in domain - he can not match rules setup with access role objects, BUT can with LDAP objects&lt;BR /&gt;When user is external, but he/she does have account in domain - same behaviour -&amp;nbsp;he can not match rules setup with access role objects, BUT can with LDAP objects&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looks like AR objects are working only with corporate windows laptops.&lt;BR /&gt;Is AR "examinating" user differently then LDAP? apparently yes, but do we have exact reason?&lt;/P&gt;&lt;P&gt;We are using R80.30, Take219, Identity Awareness with Identity collector&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot for hints&lt;/P&gt;</description>
    <pubDate>Thu, 11 Feb 2021 11:13:45 GMT</pubDate>
    <dc:creator>Miroslav_Guoth</dc:creator>
    <dc:date>2021-02-11T11:13:45Z</dc:date>
    <item>
      <title>LDAP group vs Access role objects</title>
      <link>https://community.checkpoint.com/t5/General-Topics/LDAP-group-vs-Access-role-objects/m-p/110532#M20909</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;Could you please point to link where difference between LDAP group and access role is described?&lt;BR /&gt;My issue is:&lt;BR /&gt;We do have used both in our policy (LDAP &amp;amp; AR) objects.&lt;BR /&gt;When user, whose laptop is in domain - meaning internal user with windows - he can match rules setup with access role objects.&lt;BR /&gt;When user, whose laptop isn't in domain, but user is still internal and his account is in domain - he can not match rules setup with access role objects, BUT can with LDAP objects&lt;BR /&gt;When user is external, but he/she does have account in domain - same behaviour -&amp;nbsp;he can not match rules setup with access role objects, BUT can with LDAP objects&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looks like AR objects are working only with corporate windows laptops.&lt;BR /&gt;Is AR "examinating" user differently then LDAP? apparently yes, but do we have exact reason?&lt;/P&gt;&lt;P&gt;We are using R80.30, Take219, Identity Awareness with Identity collector&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot for hints&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 11:13:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/LDAP-group-vs-Access-role-objects/m-p/110532#M20909</guid>
      <dc:creator>Miroslav_Guoth</dc:creator>
      <dc:date>2021-02-11T11:13:45Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP group vs Access role objects</title>
      <link>https://community.checkpoint.com/t5/General-Topics/LDAP-group-vs-Access-role-objects/m-p/110582#M20915</link>
      <description>&lt;P&gt;It comes down to how the identity is acquired.&lt;/P&gt;
&lt;P&gt;If it is acquired via an Identity Awareness mechanism (AD Query, Identity Collector, etc), an Access Role is the correct thing to use.&lt;BR /&gt;LDAP Groups are a more “legacy” mechanism that existed well before Identity Awareness.&lt;BR /&gt;Remote Access rules are the most obvious (to me) use of these today,&amp;nbsp;but even Remote Access can be an identity source in Identity Awareness (if you enable it).&lt;BR /&gt;There might be a couple other instances where they are still needed/useful that I’m not remembering offhand.&lt;/P&gt;
&lt;P&gt;I’d have to see a more precise example of how you’re using it to explain why you’d do that versus use an Access Role.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 16:44:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/LDAP-group-vs-Access-role-objects/m-p/110582#M20915</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-02-11T16:44:26Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP group vs Access role objects</title>
      <link>https://community.checkpoint.com/t5/General-Topics/LDAP-group-vs-Access-role-objects/m-p/110780#M20925</link>
      <description>&lt;P&gt;Thanks a lot, it did make more light &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;So If I understand correctly, AR, is working directly with IA mechanism when LDAP is different method which doesn't rely anyhow on IA mechanism&lt;BR /&gt;&lt;BR /&gt;Is there anywhere described how LDAP works on lower level?&lt;/P&gt;&lt;P&gt;My case is, as you described, user connects via Remote Access with certificate authentication. I had rule based only on AR object - it didn't match. AR object matched specific AD group where user belongs to. I created Legacy object, in very same way, to match Any user in that group - rule is being hit now.&lt;BR /&gt;So I believe, once DNS is pushed to domain laptop, laptop knows Domain controllers and automatically connect there. Based on that IA knows user's identity.&lt;BR /&gt;However if laptop is not in domain (Mac / Linux), Domain cotrollers are not "point of interest" for them?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Feb 2021 07:20:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/LDAP-group-vs-Access-role-objects/m-p/110780#M20925</guid>
      <dc:creator>Miroslav_Guoth</dc:creator>
      <dc:date>2021-02-15T07:20:42Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP group vs Access role objects</title>
      <link>https://community.checkpoint.com/t5/General-Topics/LDAP-group-vs-Access-role-objects/m-p/110839#M20930</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With Identity Awareness, two things are happening at different times:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Acquire the name/IP association (done with AD Query, Identity Collector, API, Captive Portal, or other methods you configure)&lt;/LI&gt;
&lt;LI&gt;Look up the groups associated with the user (via LDAP) to calculate the Access Roles that apply to that IP&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Prior to Identity Awareness, there were different Security Servers (think proxies) and Remote Access that each acquired an identity as part of authenticating the connection.&lt;BR /&gt;The LDAP groups were acquired at that point but not shared between each other.&lt;/P&gt;
&lt;P&gt;All you need to do is enable Remote Access as an identity source in Identity Awareness.&lt;BR /&gt;This is done in the relevant gateway object in the Identity Awareness section.&lt;BR /&gt;Then you can use the Access Role to authenticate Remote Access users and not the LDAP group.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Feb 2021 18:44:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/LDAP-group-vs-Access-role-objects/m-p/110839#M20930</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-02-15T18:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP group vs Access role objects</title>
      <link>https://community.checkpoint.com/t5/General-Topics/LDAP-group-vs-Access-role-objects/m-p/110878#M20934</link>
      <description>&lt;P&gt;I do have that enabled.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/10571iF36C8FBF1EA19CB0/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The thing is, that IA blade is not turned on when laptop outside of domain connects to GW:&lt;BR /&gt;Domain laptop:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/10570iF1EEA7CB3F4ADF47/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Laptop not in domain:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/10569i139E6F39531736A2/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Both users are connected to same vpn on same GW and outputs are from same GW&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 08:22:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/LDAP-group-vs-Access-role-objects/m-p/110878#M20934</guid>
      <dc:creator>Miroslav_Guoth</dc:creator>
      <dc:date>2021-02-16T08:22:33Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP group vs Access role objects</title>
      <link>https://community.checkpoint.com/t5/General-Topics/LDAP-group-vs-Access-role-objects/m-p/110939#M20936</link>
      <description>&lt;P&gt;Is the Mac registered in the domain at all?&lt;BR /&gt;There won't be a machine identity without that for sure and likely, something that triggers Kerberos authentication with AD from the machine (you can force with kinit).&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 17:08:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/LDAP-group-vs-Access-role-objects/m-p/110939#M20936</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-02-16T17:08:08Z</dc:date>
    </item>
  </channel>
</rss>

