<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block active directory user on firewall without associated group on Spark 1570 in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Block-active-directory-user-on-firewall-without-associated-group/m-p/181835#M8958</link>
    <description>&lt;P&gt;If its a Locally Managed appliance, this is a known limitation that you cannot select specific users from AD on SMB appliances.&lt;BR /&gt;&lt;BR /&gt;See &lt;A href="https://support.checkpoint.com/results/sk/sk105977" target="_self"&gt;sk105977 -&amp;nbsp;There is no option to add specific Active Directory users and organization units inside policy rules, when using Identity Awareness blade on SMB appliances&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;&amp;gt;&amp;nbsp;&amp;nbsp;This is the current design for locally managed SMB appliances. It is a best practice to use Active Directory groups to make maintenance easier.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 24 May 2023 00:42:53 GMT</pubDate>
    <dc:creator>Tom_Hinoue</dc:creator>
    <dc:date>2023-05-24T00:42:53Z</dc:date>
    <item>
      <title>Block active directory user on firewall without associated group on Spark 1570</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Block-active-directory-user-on-firewall-without-associated-group/m-p/181732#M8954</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;Is it possible to block internet access through the firewall to a specific user in the active directory without creating an AD group?&lt;BR /&gt;I have a Spark 1570 with Gaia Embedded R81.10.05&lt;/P&gt;&lt;P&gt;I know it's possible to list the AD groups but I can't list the users...&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2023 10:21:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Block-active-directory-user-on-firewall-without-associated-group/m-p/181732#M8954</guid>
      <dc:creator>jorgemsassuncao</dc:creator>
      <dc:date>2023-05-23T10:21:20Z</dc:date>
    </item>
    <item>
      <title>Re: Block active directory user on firewall without associated group on Spark 1570</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Block-active-directory-user-on-firewall-without-associated-group/m-p/181822#M8957</link>
      <description>&lt;P&gt;Unfortunately, there is no way to refer to a specific user in LDAP, only the group(s) they are a part of.&lt;BR /&gt;This sounds like a permissions issue with your AD user.&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2023 19:20:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Block-active-directory-user-on-firewall-without-associated-group/m-p/181822#M8957</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-05-23T19:20:46Z</dc:date>
    </item>
    <item>
      <title>Re: Block active directory user on firewall without associated group on Spark 1570</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Block-active-directory-user-on-firewall-without-associated-group/m-p/181835#M8958</link>
      <description>&lt;P&gt;If its a Locally Managed appliance, this is a known limitation that you cannot select specific users from AD on SMB appliances.&lt;BR /&gt;&lt;BR /&gt;See &lt;A href="https://support.checkpoint.com/results/sk/sk105977" target="_self"&gt;sk105977 -&amp;nbsp;There is no option to add specific Active Directory users and organization units inside policy rules, when using Identity Awareness blade on SMB appliances&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;&amp;gt;&amp;nbsp;&amp;nbsp;This is the current design for locally managed SMB appliances. It is a best practice to use Active Directory groups to make maintenance easier.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 00:42:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Block-active-directory-user-on-firewall-without-associated-group/m-p/181835#M8958</guid>
      <dc:creator>Tom_Hinoue</dc:creator>
      <dc:date>2023-05-24T00:42:53Z</dc:date>
    </item>
    <item>
      <title>Re: Block active directory user on firewall without associated group on Spark 1570</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Block-active-directory-user-on-firewall-without-associated-group/m-p/181837#M8959</link>
      <description>&lt;P&gt;AS&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8345"&gt;@Tom_Hinoue&lt;/a&gt;&amp;nbsp;said, it is limitation for locally managed appliance. If its centrally managed, should be doable with access role, if you add say a group from AD server that contains a single user.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 01:17:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Block-active-directory-user-on-firewall-without-associated-group/m-p/181837#M8959</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-24T01:17:48Z</dc:date>
    </item>
  </channel>
</rss>

