<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to restrict the MS Active Directory Authentication for remote access VPN  to specific AD Gro in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-restrict-the-MS-Active-Directory-Authentication-for/m-p/114076#M10883</link>
    <description>&lt;P&gt;me too&lt;/P&gt;</description>
    <pubDate>Fri, 19 Mar 2021 11:07:19 GMT</pubDate>
    <dc:creator>PointOfChecking</dc:creator>
    <dc:date>2021-03-19T11:07:19Z</dc:date>
    <item>
      <title>How to restrict the MS Active Directory Authentication for remote access VPN  to specific AD Groups</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-restrict-the-MS-Active-Directory-Authentication-for/m-p/80501#M10870</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;we are using AD users for remote access VPN. We have defined some Access Roles for serveral AD Groups, but,&amp;nbsp; w&lt;SPAN&gt;e have observed every AD user can log in via VPN client (end point sercurity),&amp;nbsp;regardless the user has a security policy associated or not. If the user is not included in a security policy, of course, they are not able to access to&amp;nbsp; some where, but, they still can do the log in successfully on the VPN client.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;So, somehow, we would like to allow the AD authentication for remote access VPN&amp;nbsp; just for those users belonging to the Access Roles or for some specific AD Groups.&lt;/P&gt;&lt;P&gt;How could we do this configuration?&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 16:34:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-restrict-the-MS-Active-Directory-Authentication-for/m-p/80501#M10870</guid>
      <dc:creator>Fzahinos</dc:creator>
      <dc:date>2020-04-01T16:34:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict the MS Active Directory Authentication for remote access VPN  to specific AD Gro</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-restrict-the-MS-Active-Directory-Authentication-for/m-p/80527#M10871</link>
      <description>Fzahinos,&lt;BR /&gt;&lt;BR /&gt;on the RemoteAccess community you can restrict the access to VPN via local or LDAP user group. Remove the normally shown „all users“ and add your own ldap group. Every user not being member of this group will be not allowed to connect.&lt;BR /&gt;&lt;BR /&gt;Wolfgang</description>
      <pubDate>Wed, 01 Apr 2020 19:20:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-restrict-the-MS-Active-Directory-Authentication-for/m-p/80527#M10871</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-04-01T19:20:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict the MS Active Directory Authentication for remote access VPN  to specific AD Gro</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-restrict-the-MS-Active-Directory-Authentication-for/m-p/80565#M10872</link>
      <description>&lt;P&gt;Thanks Wolfgang.&lt;/P&gt;&lt;P&gt;I have a doubt about this solution. In case an user is included in two LDAP or Users Local Groups, shoud I define the two LDAP&amp;nbsp; Groups as Participant User Groups?&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Fzahinos.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Apr 2020 07:15:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-restrict-the-MS-Active-Directory-Authentication-for/m-p/80565#M10872</guid>
      <dc:creator>Fzahinos</dc:creator>
      <dc:date>2020-04-02T07:15:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict the MS Active Directory Authentication for remote access VPN  to specific AD Gro</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-restrict-the-MS-Active-Directory-Authentication-for/m-p/80579#M10873</link>
      <description>Fzahinos,&lt;BR /&gt;if the user is in more then one Group, one Group is enough to allow the remote Access.&lt;BR /&gt;We are using normal rules with access_roles as source for allowing the specific access to Destination and services inside the Network.&lt;BR /&gt;With the group on the remote access community we're allowing the  generally access to VPN. For this we created a new group in ActiveDirectory and reference them there. Now we can regulate which users can generally connect via remote access, regardless the access_roles.&lt;BR /&gt;Wolfgang</description>
      <pubDate>Thu, 02 Apr 2020 08:54:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-restrict-the-MS-Active-Directory-Authentication-for/m-p/80579#M10873</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-04-02T08:54:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict the MS Active Directory Authentication for remote access VPN  to specific AD Gro</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-restrict-the-MS-Active-Directory-Authentication-for/m-p/80585#M10874</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;but in case you use access role on rules than you need to create ldap group to filter on the remote access community, bit annoying&lt;/P&gt;&lt;P&gt;Fabio&lt;/P&gt;</description>
      <pubDate>Thu, 02 Apr 2020 09:54:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-restrict-the-MS-Active-Directory-Authentication-for/m-p/80585#M10874</guid>
      <dc:creator>Bac26</dc:creator>
      <dc:date>2020-04-02T09:54:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict the MS Active Directory Authentication for remote access VPN  to specific AD Gro</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-restrict-the-MS-Active-Directory-Authentication-for/m-p/80598#M10875</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/18749"&gt;@Bac26&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;yes you are right, it's little bit confusing.&lt;/P&gt;
&lt;P&gt;But you can add only local or ldap groups to the remote access community, it would be better with a normal access role but that's how it works. Maybe one day Check Point will allow access roles with all configurations, but at the moment some things can be done only with ldap-groups&lt;/P&gt;
&lt;P&gt;We added there only one ldap-group named "remote_access_allow_general". This is configured in two minutes and then you can forget about ldap-groups&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Thu, 02 Apr 2020 11:48:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-restrict-the-MS-Active-Directory-Authentication-for/m-p/80598#M10875</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-04-02T11:48:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict the MS Active Directory Authentication for remote access VPN  to specific AD Gro</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-restrict-the-MS-Active-Directory-Authentication-for/m-p/80599#M10876</link>
      <description>&lt;P&gt;&lt;SPAN&gt;what do you mean exaclty with "remote_access_allow_general"? anyway if you have different access role group you will need the matching one the remote access community, if not any user anyway will log in (even after without have access to resources)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Apr 2020 11:59:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-restrict-the-MS-Active-Directory-Authentication-for/m-p/80599#M10876</guid>
      <dc:creator>Bac26</dc:creator>
      <dc:date>2020-04-02T11:59:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict the MS Active Directory Authentication for remote access VPN  to specific AD Gro</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-restrict-the-MS-Active-Directory-Authentication-for/m-p/80600#M10877</link>
      <description>He means the LDAP group is specified only on first implementation and every VPN user is added to this group through AD.&lt;BR /&gt;Later on this group doesn't need to be changed configuration-wise in Check Point and only access roles need to be configured/modified to allow specific access on rules.</description>
      <pubDate>Thu, 02 Apr 2020 12:10:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-restrict-the-MS-Active-Directory-Authentication-for/m-p/80600#M10877</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2020-04-02T12:10:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict the MS Active Directory Authentication for remote access VPN  to specific AD Gro</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-restrict-the-MS-Active-Directory-Authentication-for/m-p/80603#M10878</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1433"&gt;@Norbert_Bohusch&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you're right, thanks for clarification &lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;With this configuration anyone can login via VPN client, regardless the configured access rules.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RemoteAccess_all.PNG" style="width: 596px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5321iA360D119E6F76C5C/image-size/large?v=v2&amp;amp;px=999" role="button" title="RemoteAccess_all.PNG" alt="RemoteAccess_all.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;With this configuration the login via vpn client is failing if the user is not member of the shown group. This is to restrict the generally access to the remote access vpn.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RemoteAccess_group.PNG" style="width: 591px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5322i2B2BAB082789C5CA/image-size/large?v=v2&amp;amp;px=999" role="button" title="RemoteAccess_group.PNG" alt="RemoteAccess_group.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Apr 2020 12:25:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-restrict-the-MS-Active-Directory-Authentication-for/m-p/80603#M10878</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-04-02T12:25:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict the MS Active Directory Authentication for remote access VPN  to specific AD Gro</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-restrict-the-MS-Active-Directory-Authentication-for/m-p/80605#M10879</link>
      <description>&lt;P&gt;Ok got it what you mean!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;BR /&gt;Fabio&lt;/P&gt;</description>
      <pubDate>Thu, 02 Apr 2020 12:44:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-restrict-the-MS-Active-Directory-Authentication-for/m-p/80605#M10879</guid>
      <dc:creator>Bac26</dc:creator>
      <dc:date>2020-04-02T12:44:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict the MS Active Directory Authentication for remote access VPN  to specific AD Gro</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-restrict-the-MS-Active-Directory-Authentication-for/m-p/81107#M10880</link>
      <description>Hi,&lt;BR /&gt;Does this works with nested groups?&lt;BR /&gt;Thanks</description>
      <pubDate>Tue, 07 Apr 2020 09:27:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-restrict-the-MS-Active-Directory-Authentication-for/m-p/81107#M10880</guid>
      <dc:creator>Rui_Gomes_PT</dc:creator>
      <dc:date>2020-04-07T09:27:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict the MS Active Directory Authentication for remote access VPN  to specific AD Gro</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-restrict-the-MS-Active-Directory-Authentication-for/m-p/81114#M10881</link>
      <description>&lt;P&gt;Not sure, you have to try.&lt;/P&gt;
&lt;P&gt;Following&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk107472" target="_blank" rel="noopener"&gt;Mobile Access and Endpoint clients LDAP nested groups are not enforced correctly&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;it's not supported. But I think this article is meaning the access rules itself and not the group for the remote access community.&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2020 11:34:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-restrict-the-MS-Active-Directory-Authentication-for/m-p/81114#M10881</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-04-07T11:34:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict the MS Active Directory Authentication for remote access VPN  to specific AD Gro</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-restrict-the-MS-Active-Directory-Authentication-for/m-p/81601#M10882</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm unable to either add custom ldap group or delete the default All Users group user Participant Users Group.&amp;nbsp; Am i missing something?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;</description>
      <pubDate>Sat, 11 Apr 2020 14:51:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-restrict-the-MS-Active-Directory-Authentication-for/m-p/81601#M10882</guid>
      <dc:creator>Rajnesh_Chand</dc:creator>
      <dc:date>2020-04-11T14:51:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict the MS Active Directory Authentication for remote access VPN  to specific AD Gro</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-restrict-the-MS-Active-Directory-Authentication-for/m-p/114076#M10883</link>
      <description>&lt;P&gt;me too&lt;/P&gt;</description>
      <pubDate>Fri, 19 Mar 2021 11:07:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-restrict-the-MS-Active-Directory-Authentication-for/m-p/114076#M10883</guid>
      <dc:creator>PointOfChecking</dc:creator>
      <dc:date>2021-03-19T11:07:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict the MS Active Directory Authentication for remote access VPN  to specific AD Gro</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-restrict-the-MS-Active-Directory-Authentication-for/m-p/114094#M10884</link>
      <description>&lt;P&gt;You also need to create a new LDAP Group in the objects.&amp;nbsp; Not a User Access Group.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Mar 2021 15:59:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-restrict-the-MS-Active-Directory-Authentication-for/m-p/114094#M10884</guid>
      <dc:creator>PointOfChecking</dc:creator>
      <dc:date>2021-03-19T15:59:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict the MS Active Directory Authentication for remote access VPN  to specific AD Gro</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-restrict-the-MS-Active-Directory-Authentication-for/m-p/114468#M10885</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;just updating the thread that the issue raised by&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/58146"&gt;@PointOfChecking&lt;/a&gt;&amp;nbsp;, solved.&lt;/P&gt;
&lt;P&gt;In order for VPN to work as an identity source&amp;nbsp; you must enable "Remote Access" checkbox under Identity Awareness properties.&lt;/P&gt;
&lt;P&gt;it is also documented in Identity Awareness Admin Guide.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Ilya&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Mar 2021 14:19:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-restrict-the-MS-Active-Directory-Authentication-for/m-p/114468#M10885</guid>
      <dc:creator>Ilya_Yusupov</dc:creator>
      <dc:date>2021-03-24T14:19:43Z</dc:date>
    </item>
  </channel>
</rss>

