<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Properly define Ldap Group in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Properly-define-Ldap-Group/m-p/13073#M13809</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you get this figured out? I’m seeing the same thing and following&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk31841" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk31841"&gt;LDAP Configuration - Best Practice&lt;/A&gt;&amp;nbsp;it looks like the example is setup to allow anyone from AD but we only want specific users.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 21 Apr 2018 14:57:15 GMT</pubDate>
    <dc:creator>Heath</dc:creator>
    <dc:date>2018-04-21T14:57:15Z</dc:date>
    <item>
      <title>Properly define Ldap Group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Properly-define-Ldap-Group/m-p/13072#M13808</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey expert&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know this question seems more a micr****t question but still I want to give it a try since today I was struggling with that argument , create an account unit and make the Identity Awareness went pretty fine .&lt;/P&gt;&lt;P&gt;Users are authenticated with ldap ,defining an ldap group in such way&lt;/P&gt;&lt;P&gt;-Only group in branch (dn prefix) CN=test,OU=customer,DC=customer,DC=local does not seems to match the group test in the OU customer and the remote access traffic are hitting clean up rule&lt;/P&gt;&lt;P&gt;while define the group in the way&lt;/P&gt;&lt;P&gt;-Only Sub Tree CN=Users DC=customer,DC=local match my remote access rule with as a source the defined ldap group&lt;/P&gt;&lt;P&gt;Triple checked the path on the domain controller , looks like I'm missing something obvious here , if someone got some hint I'll appreciate it&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64338_pastedImage_1.png" style="width: auto; height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Apr 2018 16:12:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Properly-define-Ldap-Group/m-p/13072#M13808</guid>
      <dc:creator>Marco_Valenti</dc:creator>
      <dc:date>2018-04-05T16:12:54Z</dc:date>
    </item>
    <item>
      <title>Re: Properly define Ldap Group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Properly-define-Ldap-Group/m-p/13073#M13809</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you get this figured out? I’m seeing the same thing and following&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk31841" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk31841"&gt;LDAP Configuration - Best Practice&lt;/A&gt;&amp;nbsp;it looks like the example is setup to allow anyone from AD but we only want specific users.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 21 Apr 2018 14:57:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Properly-define-Ldap-Group/m-p/13073#M13809</guid>
      <dc:creator>Heath</dc:creator>
      <dc:date>2018-04-21T14:57:15Z</dc:date>
    </item>
    <item>
      <title>Re: Properly define Ldap Group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Properly-define-Ldap-Group/m-p/13074#M13810</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Really not , working with some smb appliance and founding out ( I don't know if this is relevant) that the dc did not reply to the ldap query with the attribute member of so the gateway can't match the ldap group defined in the remote access rule&lt;/P&gt;&lt;P&gt;Ldap group was set in this way CN=(nameofthegroup),OU=(nameoftheouu)DC=(nameoftecompany),DC=(local)&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for pointing out the sk&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Apr 2018 06:44:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Properly-define-Ldap-Group/m-p/13074#M13810</guid>
      <dc:creator>Marco_Valenti</dc:creator>
      <dc:date>2018-04-23T06:44:47Z</dc:date>
    </item>
    <item>
      <title>Re: Properly define Ldap Group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Properly-define-Ldap-Group/m-p/13075#M13811</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The only way that I've been able to get this work is when I&amp;nbsp;set the source to 'All &lt;A href="mailto:Users@Any'...not"&gt;Users@Any'...&lt;/A&gt;I wouldn't think that's the best solution.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Apr 2018 22:49:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Properly-define-Ldap-Group/m-p/13075#M13811</guid>
      <dc:creator>Heath</dc:creator>
      <dc:date>2018-04-23T22:49:45Z</dc:date>
    </item>
    <item>
      <title>Re: Properly define Ldap Group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Properly-define-Ldap-Group/m-p/13076#M13812</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the exact same problem with my 1400 devices. Any solution to this? Just want to work with AD groups as Source in a VPN rule.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Nov 2018 14:56:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Properly-define-Ldap-Group/m-p/13076#M13812</guid>
      <dc:creator>Johnny_Sjolund</dc:creator>
      <dc:date>2018-11-28T14:56:45Z</dc:date>
    </item>
    <item>
      <title>Re: Properly define Ldap Group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Properly-define-Ldap-Group/m-p/13077#M13813</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;First, you need a group defined in AD, example "my-test-group"....then user ( your case user = "test" )has to be part of the newly created group.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Account unit = should have selected your AD domain...possible defined earlier when you enabled "Identity Awareness blade"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then choose only group in branch....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CN= my-test-group, OU=groups&amp;nbsp; &amp;nbsp; &amp;nbsp; .... the rest of the prefix should already be populated if already had an account unit defined.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Assuming that the 1400 devices have&amp;nbsp;access available to your AD somehow...via VPN or other means.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Dec 2018 15:47:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Properly-define-Ldap-Group/m-p/13077#M13813</guid>
      <dc:creator>Sal_Previtera</dc:creator>
      <dc:date>2018-12-20T15:47:20Z</dc:date>
    </item>
    <item>
      <title>Re: Properly define Ldap Group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Properly-define-Ldap-Group/m-p/115928#M13814</link>
      <description>&lt;P&gt;Good day,&lt;/P&gt;&lt;P&gt;Anyone already solved this issue? Im having the same problem whereas using the group doesnt match the rulebase.&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 13 Apr 2021 11:59:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Properly-define-Ldap-Group/m-p/115928#M13814</guid>
      <dc:creator>Richard_Anton_V</dc:creator>
      <dc:date>2021-04-13T11:59:46Z</dc:date>
    </item>
  </channel>
</rss>

