<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: cloud SMP role definitions in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/cloud-SMP-role-definitions/m-p/116472#M5094</link>
    <description>&lt;P&gt;From what the experts tell me, this is not possible with SMP currently.&lt;BR /&gt;You can't give access to specific gateways, only specific actions within the SMP with apply to all gateways.&lt;BR /&gt;The only way to achieve this at the moment is for the user to connect to their gateway (either directly or via Reach My Device).&lt;/P&gt;</description>
    <pubDate>Wed, 21 Apr 2021 01:41:02 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-04-21T01:41:02Z</dc:date>
    <item>
      <title>cloud SMP role definitions</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/cloud-SMP-role-definitions/m-p/116242#M5085</link>
      <description>&lt;P&gt;OK so I am finally getting back to re-evaluating cloud SMP for my users that are purchasing 1500 appliances.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like a user to be able to login and only see his devices/plans/roles on the cloud SMP.&amp;nbsp; He should not be able to see any other users gateways.&lt;/P&gt;&lt;P&gt;At this time I am not worried about the user seeing logs for other gateways.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this even possible?&amp;nbsp; I am trying to filter using the Intersects(gateways, CurrentUser.gateways), however I must not be giving enough access, it appears that we need access to user and all gateways to see this.&amp;nbsp; This is from the SMP 12.30 Admin guide P111?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone ever do this kind of access role?&amp;nbsp; I am trying to understand all the fields that we could match.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to match on a user field, for example user-&amp;gt;custom field-&amp;gt;UserGroup access and gateway-&amp;gt;custom field -&amp;gt; GWgroup, then give access if CurrentUser.UserGroup&amp;nbsp; == Gateway.GWgroup?&lt;/P&gt;&lt;P&gt;Cloud SMP 12.30&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 17 Apr 2021 19:32:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/cloud-SMP-role-definitions/m-p/116242#M5085</guid>
      <dc:creator>Ted_Serreyn</dc:creator>
      <dc:date>2021-04-17T19:32:16Z</dc:date>
    </item>
    <item>
      <title>Re: cloud SMP role definitions</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/cloud-SMP-role-definitions/m-p/116472#M5094</link>
      <description>&lt;P&gt;From what the experts tell me, this is not possible with SMP currently.&lt;BR /&gt;You can't give access to specific gateways, only specific actions within the SMP with apply to all gateways.&lt;BR /&gt;The only way to achieve this at the moment is for the user to connect to their gateway (either directly or via Reach My Device).&lt;/P&gt;</description>
      <pubDate>Wed, 21 Apr 2021 01:41:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/cloud-SMP-role-definitions/m-p/116472#M5094</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-04-21T01:41:02Z</dc:date>
    </item>
    <item>
      <title>Re: cloud SMP role definitions</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/cloud-SMP-role-definitions/m-p/116489#M5095</link>
      <description>&lt;P&gt;Every user buying a 1500 gets one Cloud Management license for it included in the deal. So he has his own Cloud Management and therefore will see no other GWs.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Apr 2021 08:10:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/cloud-SMP-role-definitions/m-p/116489#M5095</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-04-21T08:10:20Z</dc:date>
    </item>
    <item>
      <title>Re: cloud SMP role definitions</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/cloud-SMP-role-definitions/m-p/116663#M5103</link>
      <description>&lt;P&gt;And why would I want every customer that needs help managing their firewall in their own SMP?&amp;nbsp; That kind of defeats the purpose.&amp;nbsp; I don't want to login to every firewall, so I want to use SMP.&amp;nbsp; Because of this I don't want to login to every different SMP portal.&lt;/P&gt;&lt;P&gt;I want to work smarter, not harder.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 16:34:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/cloud-SMP-role-definitions/m-p/116663#M5103</guid>
      <dc:creator>Ted_Serreyn</dc:creator>
      <dc:date>2021-04-22T16:34:53Z</dc:date>
    </item>
    <item>
      <title>Re: cloud SMP role definitions</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/cloud-SMP-role-definitions/m-p/116664#M5104</link>
      <description>&lt;P&gt;It is possible, we have done it.&amp;nbsp; The key is the access roles rule for Gateways.&amp;nbsp; Matches(name,"gwprefix.+")&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 16:38:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/cloud-SMP-role-definitions/m-p/116664#M5104</guid>
      <dc:creator>Ted_Serreyn</dc:creator>
      <dc:date>2021-04-22T16:38:43Z</dc:date>
    </item>
  </channel>
</rss>

