<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Do not view LDAP groups in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Do-not-view-LDAP-groups/m-p/110850#M9160</link>
    <description>&lt;P&gt;For something like that, use accessroles, not remote access groups.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Mon, 15 Feb 2021 21:40:44 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2021-02-15T21:40:44Z</dc:date>
    <item>
      <title>Do not view LDAP groups</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Do-not-view-LDAP-groups/m-p/110840#M9159</link>
      <description>&lt;P&gt;Hey guys&lt;/P&gt;&lt;P&gt;I need to limit user authentication on vpn using endpoit security and even located in the community "remote access" and there is "all users" but there is no ldap groups for me to do this configuration, only the local group that I created and the local user appears .&lt;BR /&gt;In the environment I have several rules that are related to users in the ad, and I came across this situation.&lt;/P&gt;&lt;P&gt;Has anyone ever experienced this ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Feb 2021 18:48:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Do-not-view-LDAP-groups/m-p/110840#M9159</guid>
      <dc:creator>Rodrigo_Mezetti</dc:creator>
      <dc:date>2021-02-15T18:48:13Z</dc:date>
    </item>
    <item>
      <title>Re: Do not view LDAP groups</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Do-not-view-LDAP-groups/m-p/110850#M9160</link>
      <description>&lt;P&gt;For something like that, use accessroles, not remote access groups.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 15 Feb 2021 21:40:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Do-not-view-LDAP-groups/m-p/110850#M9160</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-02-15T21:40:44Z</dc:date>
    </item>
    <item>
      <title>Re: Do not view LDAP groups</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Do-not-view-LDAP-groups/m-p/110856#M9161</link>
      <description>&lt;P&gt;That doesn’t prevent you from authenticating to the VPN but it can be used to prevent you from going anywhere if you do connect.&lt;BR /&gt;Preventing you from authenticating at all using anything other than a locally defined group of locally defined users is an RFE, I believe.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 00:03:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Do-not-view-LDAP-groups/m-p/110856#M9161</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-02-16T00:03:18Z</dc:date>
    </item>
    <item>
      <title>Re: Do not view LDAP groups</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Do-not-view-LDAP-groups/m-p/110959#M9162</link>
      <description>&lt;P&gt;I made the configuration creating and users / ldap group, indicating the path of the group in the active directory that has the users inside and it worked. Now only those who are in this group are authenticated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tanks&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 20:27:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Do-not-view-LDAP-groups/m-p/110959#M9162</guid>
      <dc:creator>Rodrigo_Mezetti</dc:creator>
      <dc:date>2021-02-16T20:27:52Z</dc:date>
    </item>
    <item>
      <title>Re: Do not view LDAP groups</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Do-not-view-LDAP-groups/m-p/120146#M9163</link>
      <description>&lt;P&gt;Hey&amp;nbsp; Mate,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to do the same, could you please share the config of AD and access policy as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Karan Sharma&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 23:31:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Do-not-view-LDAP-groups/m-p/120146#M9163</guid>
      <dc:creator>Karan0587</dc:creator>
      <dc:date>2021-06-01T23:31:31Z</dc:date>
    </item>
    <item>
      <title>Re: Do not view LDAP groups</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Do-not-view-LDAP-groups/m-p/120148#M9164</link>
      <description>&lt;P&gt;hi man.. sorry my english..&lt;/P&gt;&lt;P&gt;I created an ldap group, on the right of the smartconsole in user - ldap group. I informed the full path of the OU that has the users who will be able to "authenticate in vpn"&lt;BR /&gt;example:&lt;BR /&gt;dn-prefix set box&lt;BR /&gt;CN=AUTH_VPN - ,OU=Client_vpn,OU=Group,OU=test,DC=testlocal,DC=com,DC=br which is the path you can take in active director via adsi editor&lt;/P&gt;&lt;P&gt;After that I created the rules on the blade firewall/app access rules with the access that each user can have after authenticating, and set vpn ( remote access).&lt;BR /&gt;Some accessing remote desktop, others ssh , all under different rules and stating .&lt;BR /&gt;Remember to inform the group in the VPN domain of the internal servers in the gateway or cluster properties,&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 00:49:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Do-not-view-LDAP-groups/m-p/120148#M9164</guid>
      <dc:creator>Rodrigo_Mezetti</dc:creator>
      <dc:date>2021-06-02T00:49:47Z</dc:date>
    </item>
    <item>
      <title>Re: Do not view LDAP groups</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Do-not-view-LDAP-groups/m-p/120171#M9165</link>
      <description>&lt;P&gt;Hi Rodrigo,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply so authentication is fixed following your method although i am still confused as how to restrict the ports on the basis of some security groups only for eg i am attaching a rule&amp;nbsp; which has access roles in source of security group with RDP access only and allowing 3389 tcp port.Is this the way or i have to create an inline layer underneath the actual remote access policy, can u share ur config ( blur the org details).&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 08:08:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Do-not-view-LDAP-groups/m-p/120171#M9165</guid>
      <dc:creator>Karan0587</dc:creator>
      <dc:date>2021-06-02T08:08:22Z</dc:date>
    </item>
  </channel>
</rss>

