<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to restrict a remote access user to only allowed to access to one subnet in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-restrict-a-remote-access-user-to-only-allowed-to-access/m-p/152234#M7054</link>
    <description>&lt;P&gt;Hi folks,&lt;/P&gt;&lt;P&gt;How to restrict a remote access user to only allowed to access to one subnet on spark 1600? Let say I have created a user call "UserA" and grant the remote access permission for that user. From Access Policy &amp;gt; Firewall Access Blade policy is Standard. No user awareness enabled. From Access Policy &amp;gt; Firewall Policy &amp;gt; Incoming, Internal and VPN traffic, I have a rule to allow UserA (source) to access to 192.168.10.0 (destination) for any service.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But once UserA remotes access to the office, UserA can access any internal subnet but is not restricted to only access 192.168.10.0. Is there anything I have set the CheckPoint device wrongly?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Ken&lt;/P&gt;</description>
    <pubDate>Mon, 04 Jul 2022 06:08:53 GMT</pubDate>
    <dc:creator>ken2</dc:creator>
    <dc:date>2022-07-04T06:08:53Z</dc:date>
    <item>
      <title>How to restrict a remote access user to only allowed to access to one subnet</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-restrict-a-remote-access-user-to-only-allowed-to-access/m-p/152234#M7054</link>
      <description>&lt;P&gt;Hi folks,&lt;/P&gt;&lt;P&gt;How to restrict a remote access user to only allowed to access to one subnet on spark 1600? Let say I have created a user call "UserA" and grant the remote access permission for that user. From Access Policy &amp;gt; Firewall Access Blade policy is Standard. No user awareness enabled. From Access Policy &amp;gt; Firewall Policy &amp;gt; Incoming, Internal and VPN traffic, I have a rule to allow UserA (source) to access to 192.168.10.0 (destination) for any service.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But once UserA remotes access to the office, UserA can access any internal subnet but is not restricted to only access 192.168.10.0. Is there anything I have set the CheckPoint device wrongly?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Ken&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jul 2022 06:08:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-restrict-a-remote-access-user-to-only-allowed-to-access/m-p/152234#M7054</guid>
      <dc:creator>ken2</dc:creator>
      <dc:date>2022-07-04T06:08:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict a remote access user to only allowed to access to one subnet</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-restrict-a-remote-access-user-to-only-allowed-to-access/m-p/152238#M7055</link>
      <description>&lt;P&gt;Please add screenshots here&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jul 2022 07:50:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-restrict-a-remote-access-user-to-only-allowed-to-access/m-p/152238#M7055</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-07-04T07:50:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict a remote access user to only allowed to access to one subnet</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-restrict-a-remote-access-user-to-only-allowed-to-access/m-p/152241#M7056</link>
      <description>&lt;P&gt;When enabling RA VPN, you check "allow traffic from Remote Access users" and a buildt-in rule is enabled. Disable it and your rule will work.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jul 2022 08:02:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-restrict-a-remote-access-user-to-only-allowed-to-access/m-p/152241#M7056</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-07-04T08:02:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict a remote access user to only allowed to access to one subnet</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-restrict-a-remote-access-user-to-only-allowed-to-access/m-p/152250#M7057</link>
      <description>&lt;P&gt;Here are the screenshots...&amp;nbsp;&lt;/P&gt;&lt;P&gt;UserA has remote access granted&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="userA_setting.png" style="width: 550px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17093i98609385E677897D/image-size/large?v=v2&amp;amp;px=999" role="button" title="userA_setting.png" alt="userA_setting.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;From the Incoming, Internal and VPN traffic, I have created Onlyto Network object group in which only contain the 192.168.10.0 subnet.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="userA.png" style="width: 724px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17094i27AEDB630DA661FF/image-size/large?v=v2&amp;amp;px=999" role="button" title="userA.png" alt="userA.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bladesetting.PNG" style="width: 741px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17095iD1B6E8EF35CFEB11/image-size/large?v=v2&amp;amp;px=999" role="button" title="bladesetting.PNG" alt="bladesetting.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;There is another auto Generated rules referring to VPN Remote Access in which I do not have a clue of what it is.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="autogeneratedRule.PNG" style="width: 695px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17096i9D1C0779B4AC951F/image-size/large?v=v2&amp;amp;px=999" role="button" title="autogeneratedRule.PNG" alt="autogeneratedRule.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="userAwareness.PNG" style="width: 709px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17097iFB06E4719CF0E775/image-size/large?v=v2&amp;amp;px=999" role="button" title="userAwareness.PNG" alt="userAwareness.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks _Val_&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jul 2022 08:26:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-restrict-a-remote-access-user-to-only-allowed-to-access/m-p/152250#M7057</guid>
      <dc:creator>ken2</dc:creator>
      <dc:date>2022-07-04T08:26:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict a remote access user to only allowed to access to one subnet</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-restrict-a-remote-access-user-to-only-allowed-to-access/m-p/152252#M7058</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi, thanks for you reply, too. Do you mean to uncheck the Allow traffic from Remote Access users checkbox in order to get the rule valid? If I uncheck the box, can UserA still be able to do remote access from the outside world?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="raSetting.PNG" style="width: 704px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17098i301D17F3C4B01258/image-size/large?v=v2&amp;amp;px=999" role="button" title="raSetting.PNG" alt="raSetting.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jul 2022 08:29:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-restrict-a-remote-access-user-to-only-allowed-to-access/m-p/152252#M7058</guid>
      <dc:creator>ken2</dc:creator>
      <dc:date>2022-07-04T08:29:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict a remote access user to only allowed to access to one subnet</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-restrict-a-remote-access-user-to-only-allowed-to-access/m-p/152253#M7059</link>
      <description>&lt;P&gt;If there is a manual rule granting access to UserA he will - the other 14 users have no access then without new rules...&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jul 2022 08:33:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-restrict-a-remote-access-user-to-only-allowed-to-access/m-p/152253#M7059</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-07-04T08:33:51Z</dc:date>
    </item>
  </channel>
</rss>

