<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mobile Access - restrict SNX with role based access in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-restrict-SNX-with-role-based-access/m-p/182783#M4875</link>
    <description>&lt;P&gt;Does it not give you option below in the rule?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21193i3D7FB0FD39B91FFF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
    <pubDate>Wed, 31 May 2023 18:37:26 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-05-31T18:37:26Z</dc:date>
    <item>
      <title>Mobile Access - restrict SNX with role based access</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-restrict-SNX-with-role-based-access/m-p/182763#M4874</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have our Mobile Access portal up and running, and I'm trying to restrict the SNX/Native Application portion to only users belonging to specific AD groups, and published web applications to others.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Right now, anyone with portal access also has Native Application/SNX access. I believe this is an issue with the way our Policy is configured.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I wanted to restrict the Native Applications menu to only users with a specific AD role, what would that policy line look like?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;here's a basic example of some CN's for what I'd want each group to access:&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2023-05-31_12h06_49.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21192iCA52F5BDB67FE0A5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2023-05-31_12h06_49.png" alt="2023-05-31_12h06_49.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've been looking at&amp;nbsp;CP_R81_MobileAccess_AdminGuide.pdf for guidance, and can restrict web Apps, but not the native apps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 16:13:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-restrict-SNX-with-role-based-access/m-p/182763#M4874</guid>
      <dc:creator>NorthernNetGuy</dc:creator>
      <dc:date>2023-05-31T16:13:18Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - restrict SNX with role based access</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-restrict-SNX-with-role-based-access/m-p/182783#M4875</link>
      <description>&lt;P&gt;Does it not give you option below in the rule?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21193i3D7FB0FD39B91FFF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 18:37:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-restrict-SNX-with-role-based-access/m-p/182783#M4875</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-31T18:37:26Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - restrict SNX with role based access</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-restrict-SNX-with-role-based-access/m-p/182784#M4876</link>
      <description>&lt;P&gt;Ah I should have specified that I'm using the unified access policy (and r81.20)&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 18:40:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-restrict-SNX-with-role-based-access/m-p/182784#M4876</guid>
      <dc:creator>NorthernNetGuy</dc:creator>
      <dc:date>2023-05-31T18:40:48Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - restrict SNX with role based access</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-restrict-SNX-with-role-based-access/m-p/182785#M4877</link>
      <description>&lt;P&gt;A kk : - ). Let me test it in the lab and see. I also have R81.20&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 18:48:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-restrict-SNX-with-role-based-access/m-p/182785#M4877</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-31T18:48:46Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - restrict SNX with role based access</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-restrict-SNX-with-role-based-access/m-p/182788#M4878</link>
      <description>&lt;P&gt;Here's a screenshot of what the policy looks like that might help with identifying my issue. I've added in rule 10-12 to try and expand the portal usage, while rule 13-14 was created by our checkpoint PS during initial deployment.&lt;/P&gt;&lt;P&gt;My main goal is to just remove the "connect" button, or the entire native apps section, for users that don't require it.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2023-05-31_14h53_49.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21195iF61843C555358837/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2023-05-31_14h53_49.png" alt="2023-05-31_14h53_49.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks for the help!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 18:59:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-restrict-SNX-with-role-based-access/m-p/182788#M4878</guid>
      <dc:creator>NorthernNetGuy</dc:creator>
      <dc:date>2023-05-31T18:59:28Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - restrict SNX with role based access</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-restrict-SNX-with-role-based-access/m-p/182789#M4879</link>
      <description>&lt;P&gt;Would you mind sharing whats in that group under services in rule 12.1 and 12.2, specifically one that ends with -RDP? I ask because based on what you mentioned, appears rule 12.1 has been hit 1M times and 12.2 only 174 times, just not sure in what time period though.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 19:06:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-restrict-SNX-with-role-based-access/m-p/182789#M4879</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-31T19:06:47Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - restrict SNX with role based access</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-restrict-SNX-with-role-based-access/m-p/182792#M4880</link>
      <description>&lt;P&gt;Ah... They reference different AD roles, however they also reference the same remote access client profile:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2023-05-31_15h14_28.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21196i29D684A9120821DF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2023-05-31_15h14_28.png" alt="2023-05-31_15h14_28.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 19:14:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-restrict-SNX-with-role-based-access/m-p/182792#M4880</guid>
      <dc:creator>NorthernNetGuy</dc:creator>
      <dc:date>2023-05-31T19:14:48Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - restrict SNX with role based access</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-restrict-SNX-with-role-based-access/m-p/182793#M4881</link>
      <description>&lt;P&gt;Sorry, I meant under services/applications column, not access role. I want to see if it works in my lab. Please blur out any sensitive info.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 19:22:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-restrict-SNX-with-role-based-access/m-p/182793#M4881</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-31T19:22:46Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - restrict SNX with role based access</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-restrict-SNX-with-role-based-access/m-p/182797#M4882</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/23907"&gt;@NorthernNetGuy&lt;/a&gt;&amp;nbsp;this is normal behaviour with unified policy and mentioned in&amp;nbsp;&lt;A title="Limitations for Mobile Access in the Unified Policy" href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_MobileAccess_AdminGuide/Content/Topics-MABG/Mobile-Access-and-Unified-Access-Policy.htm#Limitations_for_Mobile_Access_in_the_Unified_Policy" target="_blank" rel="noopener"&gt;Limitations for Mobile Access in the Unified Policy&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;„&lt;SPAN&gt;The Native Applications &lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Connect&lt;/SPAN&gt;&lt;SPAN&gt; button always shows in the &lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_mobacc_portal variable"&gt;Mobile Access Portal&lt;/SPAN&gt;&lt;SPAN&gt; when &lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_snx variable"&gt;SSL Network Extender&lt;/SPAN&gt;&lt;SPAN&gt; is enabled“&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You can restrict the access but the button will be always there.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Using the „old“ way with MobileAccess policy in SmartDashboard you can make the connect button invisible to users without rights to access. But then you loose the better features of the unified policy.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 19:29:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-restrict-SNX-with-role-based-access/m-p/182797#M4882</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2023-05-31T19:29:50Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - restrict SNX with role based access</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-restrict-SNX-with-role-based-access/m-p/182798#M4883</link>
      <description>&lt;P&gt;Ah that's my fault for not reading correctly!&lt;/P&gt;&lt;P&gt;12.1 is an internaly hsoted web application that acts as an RDP proxy:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2023-05-31_15h25_23.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21197i5C0DAB3B111BD099/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2023-05-31_15h25_23.png" alt="2023-05-31_15h25_23.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2023-05-31_15h25_57.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21198i669CF43F1D875FE1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2023-05-31_15h25_57.png" alt="2023-05-31_15h25_57.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12.2 launches the clients mstsc&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2023-05-31_15h27_36.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21199i13878D370C5B0BF8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2023-05-31_15h27_36.png" alt="2023-05-31_15h27_36.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've found that even if the user isn't in the AD group for 12.2, they still see the native application/connect button, just not quick launch link of the mstsc&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 19:30:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-restrict-SNX-with-role-based-access/m-p/182798#M4883</guid>
      <dc:creator>NorthernNetGuy</dc:creator>
      <dc:date>2023-05-31T19:30:08Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - restrict SNX with role based access</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-restrict-SNX-with-role-based-access/m-p/182799#M4884</link>
      <description>&lt;P&gt;I was literally about to send you the same link&amp;nbsp; &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;&amp;nbsp;found, but he "beat" me to it : - )&lt;/P&gt;
&lt;P&gt;I suppose it would be a limitation based on that paragraph.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 19:32:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-restrict-SNX-with-role-based-access/m-p/182799#M4884</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-31T19:32:38Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - restrict SNX with role based access</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-restrict-SNX-with-role-based-access/m-p/182800#M4885</link>
      <description>&lt;P&gt;Well that is unfortunate. It would make a big difference in clarifying things for my users, and making the portal more flexible.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I feel like this should be a reasonable feature request, so I suppose that will be in my next steps.&lt;/P&gt;&lt;P&gt;In the mean time, other that needing to manage the legacy portal from the smartview, am I going to lose much by going to the legacy policy?&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 19:40:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-restrict-SNX-with-role-based-access/m-p/182800#M4885</guid>
      <dc:creator>NorthernNetGuy</dc:creator>
      <dc:date>2023-05-31T19:40:07Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - restrict SNX with role based access</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-restrict-SNX-with-role-based-access/m-p/182801#M4886</link>
      <description>&lt;P&gt;In the words of CP Sales person who talked about this recently on a call, best way to put is that unified MA policy is way more scalable than legacy. I totally get that point.&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 19:44:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-restrict-SNX-with-role-based-access/m-p/182801#M4886</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-31T19:44:39Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - restrict SNX with role based access</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-restrict-SNX-with-role-based-access/m-p/182810#M4887</link>
      <description>&lt;P&gt;I think its pretty much same link&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;&amp;nbsp;provided&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_MobileAccess_AdminGuide/Topics-MABG/Mobile-Access-and-Unified-Access-Policy.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_MobileAccess_AdminGuide/Topics-MABG/Mobile-Access-and-Unified-Access-Policy.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 20:59:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-restrict-SNX-with-role-based-access/m-p/182810#M4887</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-31T20:59:31Z</dc:date>
    </item>
  </channel>
</rss>

