<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Checkpoint Access Role not being matched in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Checkpoint-Access-Role-not-being-matched/m-p/151123#M6741</link>
    <description>&lt;P&gt;Are there any news about this topoc.&lt;BR /&gt;We have a lab firewall with the same setup and the same problem. We are on 81 Take 68.&lt;BR /&gt;The authentication is working but the ACR is only matching if we define "Any identified User". The Username (UPN) is visible in the logs.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 17 Jun 2022 08:08:44 GMT</pubDate>
    <dc:creator>Manuel_Schulz</dc:creator>
    <dc:date>2022-06-17T08:08:44Z</dc:date>
    <item>
      <title>Checkpoint Access Role not being matched</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Checkpoint-Access-Role-not-being-matched/m-p/149381#M6740</link>
      <description>&lt;P&gt;Hello I have setup remote access vpn and using office mode + SAML Authentication (Azure Ad)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my policy I created 1 ACL to allow traffic thru the VPN to my inside networks. My "Source" value is my access role. This Access role includes my Azure Active Directory Group.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My traffic is hitting the cleanup rule . It's not being matched .&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If i change my source to 'any" - traffic is matched .&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've narrowed it down the access role being the issue .&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone have a sample configuration I could look at?&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 21:23:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Checkpoint-Access-Role-not-being-matched/m-p/149381#M6740</guid>
      <dc:creator>nflnetwork29</dc:creator>
      <dc:date>2022-05-24T21:23:57Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Access Role not being matched</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Checkpoint-Access-Role-not-being-matched/m-p/151123#M6741</link>
      <description>&lt;P&gt;Are there any news about this topoc.&lt;BR /&gt;We have a lab firewall with the same setup and the same problem. We are on 81 Take 68.&lt;BR /&gt;The authentication is working but the ACR is only matching if we define "Any identified User". The Username (UPN) is visible in the logs.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jun 2022 08:08:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Checkpoint-Access-Role-not-being-matched/m-p/151123#M6741</guid>
      <dc:creator>Manuel_Schulz</dc:creator>
      <dc:date>2022-06-17T08:08:44Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Access Role not being matched</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Checkpoint-Access-Role-not-being-matched/m-p/151133#M6742</link>
      <description>&lt;P&gt;I did some further testing. If i put a group from our ad in the ACR the permissions are granted.&amp;nbsp;&lt;BR /&gt;I think this is not the intendet purpose and there should be some configuration to change this behavoir.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jun 2022 09:51:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Checkpoint-Access-Role-not-being-matched/m-p/151133#M6742</guid>
      <dc:creator>Manuel_Schulz</dc:creator>
      <dc:date>2022-06-17T09:51:25Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Access Role not being matched</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Checkpoint-Access-Role-not-being-matched/m-p/151134#M6743</link>
      <description>&lt;P&gt;Maybe this could help.&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Access-Role-not-working/m-p/145830/highlight/true#M23059" target="_blank" rel="noopener"&gt;Hint from MattDunn&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jun 2022 09:57:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Checkpoint-Access-Role-not-being-matched/m-p/151134#M6743</guid>
      <dc:creator>Manuel_Schulz</dc:creator>
      <dc:date>2022-06-17T09:57:48Z</dc:date>
    </item>
  </channel>
</rss>

