<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Mobile access VPN and Unified policy observations in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-access-VPN-and-Unified-policy-observations/m-p/101141#M9678</link>
    <description>&lt;P&gt;VPN unified access and the rules it follows are not too easy in Check Point. Wrote down some experiences since I haven't seen any collection of this. Could you fix my perceptions to gather a better list?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You have to configure in GW object&lt;/P&gt;&lt;P&gt;- Identity Awareness: Remote Access - to make Access Role work in rule base&lt;/P&gt;&lt;P&gt;- Mobile Access: Unified Access Policy - to use Access Roles instead of old policy&lt;/P&gt;&lt;P&gt;- Rest of the Mobile Access options as you wish&lt;/P&gt;&lt;P&gt;In rule base&lt;/P&gt;&lt;P&gt;- If you use Inline layers, you cannot have a legacy user access in the same set as Access roles.&lt;/P&gt;&lt;P&gt;- If you use Ordered layers, you cannot have a legacy user access in the layer.&lt;/P&gt;&lt;P&gt;- Remote Access Community is not used in VPN column in Unified rules, but is used to allow user to use Remote Access. It is unknown if it is possible to actually create more than one Remote Access community, at least not from GUI it seems impossible. On the other hand, it is enough to put all user groups to that community to let them authenticate, but maybe it would be nice to create a second community if you want to limit the GW that the users can use.&lt;/P&gt;&lt;P&gt;- You cannot mix e.g. network objects with Access Roles, even if it lets you put one in the column.&lt;/P&gt;&lt;P&gt;In Access role objects&lt;/P&gt;&lt;P&gt;- Only LDAP users/groups OR Internal User Groups in one Access Role - not both&lt;/P&gt;&lt;P&gt;- Only LDAP users can be added directly to Access Role - not Internal users&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other things to consider?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Btw, how does "Mobile Access differ" from the "VPN clients" section in GW object? What determines which one's settings are used?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 04 Nov 2020 19:24:14 GMT</pubDate>
    <dc:creator>SamiH</dc:creator>
    <dc:date>2020-11-04T19:24:14Z</dc:date>
    <item>
      <title>Mobile access VPN and Unified policy observations</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-access-VPN-and-Unified-policy-observations/m-p/101141#M9678</link>
      <description>&lt;P&gt;VPN unified access and the rules it follows are not too easy in Check Point. Wrote down some experiences since I haven't seen any collection of this. Could you fix my perceptions to gather a better list?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You have to configure in GW object&lt;/P&gt;&lt;P&gt;- Identity Awareness: Remote Access - to make Access Role work in rule base&lt;/P&gt;&lt;P&gt;- Mobile Access: Unified Access Policy - to use Access Roles instead of old policy&lt;/P&gt;&lt;P&gt;- Rest of the Mobile Access options as you wish&lt;/P&gt;&lt;P&gt;In rule base&lt;/P&gt;&lt;P&gt;- If you use Inline layers, you cannot have a legacy user access in the same set as Access roles.&lt;/P&gt;&lt;P&gt;- If you use Ordered layers, you cannot have a legacy user access in the layer.&lt;/P&gt;&lt;P&gt;- Remote Access Community is not used in VPN column in Unified rules, but is used to allow user to use Remote Access. It is unknown if it is possible to actually create more than one Remote Access community, at least not from GUI it seems impossible. On the other hand, it is enough to put all user groups to that community to let them authenticate, but maybe it would be nice to create a second community if you want to limit the GW that the users can use.&lt;/P&gt;&lt;P&gt;- You cannot mix e.g. network objects with Access Roles, even if it lets you put one in the column.&lt;/P&gt;&lt;P&gt;In Access role objects&lt;/P&gt;&lt;P&gt;- Only LDAP users/groups OR Internal User Groups in one Access Role - not both&lt;/P&gt;&lt;P&gt;- Only LDAP users can be added directly to Access Role - not Internal users&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other things to consider?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Btw, how does "Mobile Access differ" from the "VPN clients" section in GW object? What determines which one's settings are used?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2020 19:24:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-access-VPN-and-Unified-policy-observations/m-p/101141#M9678</guid>
      <dc:creator>SamiH</dc:creator>
      <dc:date>2020-11-04T19:24:14Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile access VPN and Unified policy observations</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-access-VPN-and-Unified-policy-observations/m-p/101164#M9679</link>
      <description>&lt;P&gt;I believe R80.40+ allows mixing network and Access Roles.&lt;BR /&gt;For VPN clients, the gateway setting determines what clients are allowed to connect, the Access Role setting determines what clients are included.&lt;BR /&gt;This allows you to have a different access policy for different types of clients.&lt;/P&gt;
&lt;P&gt;And, no, there is only one remote access community.&lt;BR /&gt;You cannot create more than one.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Nov 2020 03:30:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-access-VPN-and-Unified-policy-observations/m-p/101164#M9679</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-11-05T03:30:35Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile access VPN and Unified policy observations</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-access-VPN-and-Unified-policy-observations/m-p/112511#M9680</link>
      <description>&lt;P&gt;Can I use the same rule (with native application) both with SNX client and Check Point Mobile E83.20?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Mar 2021 09:38:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-access-VPN-and-Unified-policy-observations/m-p/112511#M9680</guid>
      <dc:creator>lorenzopugnaghi</dc:creator>
      <dc:date>2021-03-05T09:38:28Z</dc:date>
    </item>
  </channel>
</rss>

