<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Not able to access native applications for AD users in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Not-able-to-access-native-applications-for-AD-users/m-p/29911#M13496</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Setup:Distributed&lt;/P&gt;&lt;P&gt;Version:R80.10 with TAKE_56&lt;/P&gt;&lt;P&gt;AD authentication for SSL VPN users stopped working after AD password expiry of non-admin user.&lt;/P&gt;&lt;P&gt;We were not able to see complete AD tree,we have manually added subdomain with parent domain,after that user is able to authenticate,but not able to access native applications.&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is working for local users,it will also work AD users if I add 'All uers" in source column of Mobile access policy.&lt;/P&gt;&lt;P&gt;But if I am adding specific AD users or LDAP groups,traffic is dropping with MAB policy with non-existant rule which is showing in logs.&lt;/P&gt;&lt;P&gt;When I am checking for drops with #fw ctl zdebug + drop | grep &amp;lt;ip&amp;gt;,can see drops as per MAB policy rule number which doesn't exist in MAB policy.&lt;/P&gt;&lt;P&gt;The rule number will be changing randomly,but the drop rule number in logs and zdebug output shows same rule number.&lt;/P&gt;&lt;P&gt;Any suggestions on this ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 11 Jun 2018 05:47:52 GMT</pubDate>
    <dc:creator>nagaraja_cs</dc:creator>
    <dc:date>2018-06-11T05:47:52Z</dc:date>
    <item>
      <title>Not able to access native applications for AD users</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Not-able-to-access-native-applications-for-AD-users/m-p/29911#M13496</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Setup:Distributed&lt;/P&gt;&lt;P&gt;Version:R80.10 with TAKE_56&lt;/P&gt;&lt;P&gt;AD authentication for SSL VPN users stopped working after AD password expiry of non-admin user.&lt;/P&gt;&lt;P&gt;We were not able to see complete AD tree,we have manually added subdomain with parent domain,after that user is able to authenticate,but not able to access native applications.&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is working for local users,it will also work AD users if I add 'All uers" in source column of Mobile access policy.&lt;/P&gt;&lt;P&gt;But if I am adding specific AD users or LDAP groups,traffic is dropping with MAB policy with non-existant rule which is showing in logs.&lt;/P&gt;&lt;P&gt;When I am checking for drops with #fw ctl zdebug + drop | grep &amp;lt;ip&amp;gt;,can see drops as per MAB policy rule number which doesn't exist in MAB policy.&lt;/P&gt;&lt;P&gt;The rule number will be changing randomly,but the drop rule number in logs and zdebug output shows same rule number.&lt;/P&gt;&lt;P&gt;Any suggestions on this ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Jun 2018 05:47:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Not-able-to-access-native-applications-for-AD-users/m-p/29911#M13496</guid>
      <dc:creator>nagaraja_cs</dc:creator>
      <dc:date>2018-06-11T05:47:52Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to access native applications for AD users</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Not-able-to-access-native-applications-for-AD-users/m-p/29912#M13497</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would engage with the TAC.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Jun 2018 18:05:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Not-able-to-access-native-applications-for-AD-users/m-p/29912#M13497</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-06-11T18:05:05Z</dc:date>
    </item>
  </channel>
</rss>

