<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: rule with access role does not match in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/rule-with-access-role-does-not-match/m-p/183818#M9025</link>
    <description>&lt;P&gt;Remember that "groups" come from LDAP and the gateway itself needs to be able to talk to the relevant LDAP server to retrieve them.&lt;BR /&gt;Have you checked this?&lt;/P&gt;</description>
    <pubDate>Mon, 12 Jun 2023 15:05:20 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-06-12T15:05:20Z</dc:date>
    <item>
      <title>rule with access role does not match</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/rule-with-access-role-does-not-match/m-p/183545#M9022</link>
      <description>&lt;P&gt;central managed SMB gateway (1570, Smart-1 cloud), LDAP-Account unit with enabled ad-proxy feature.&lt;/P&gt;
&lt;P&gt;We can browse the local ActiveDirectory and create access roles with AD groups. For remote access we create a rule with the access role as source. Users can authenticate with their AD accounts successful, but connections to internal resources are dropped. Changing the source to „any“ everything is working fine.&lt;/P&gt;
&lt;P&gt;On the gateways Identity Awareness settings only remote access is enabled. I think this should be enough, we need access roles only for remote access. But it looks like the users are not identified.&lt;/P&gt;
&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 18:57:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/rule-with-access-role-does-not-match/m-p/183545#M9022</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2023-06-07T18:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: rule with access role does not match</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/rule-with-access-role-does-not-match/m-p/183818#M9025</link>
      <description>&lt;P&gt;Remember that "groups" come from LDAP and the gateway itself needs to be able to talk to the relevant LDAP server to retrieve them.&lt;BR /&gt;Have you checked this?&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2023 15:05:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/rule-with-access-role-does-not-match/m-p/183818#M9025</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-12T15:05:20Z</dc:date>
    </item>
    <item>
      <title>Re: rule with access role does not match</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/rule-with-access-role-does-not-match/m-p/183863#M9027</link>
      <description>&lt;P&gt;Yes, this works. We are using the same gateway as AD-proxy and we have no problem discovering the AD via this AD-proxy and adding users from AD to the accessrole.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2023 07:34:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/rule-with-access-role-does-not-match/m-p/183863#M9027</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2023-06-13T07:34:14Z</dc:date>
    </item>
    <item>
      <title>Re: rule with access role does not match</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/rule-with-access-role-does-not-match/m-p/183908#M9030</link>
      <description>&lt;P&gt;I suspect AD Proxy and pdp are occurring through different code paths.&lt;BR /&gt;Did you actually check on the SMB gateway itself that it can reach LDAP and is making the appropriate LDAP queries?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2023 17:51:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/rule-with-access-role-does-not-match/m-p/183908#M9030</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-13T17:51:43Z</dc:date>
    </item>
  </channel>
</rss>

