Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Martijn
MVP Platinum
MVP Platinum
Jump to solution

Security Group Tag from Cisco ISE not assigned to Access Role

Hi All,

Customer has a R82 environment with a internal cluster and would like to use Security Group Tags from Cisco ISE to create access rules.

We have configured an Identity Collector and configured Cisco ISE as the identity source. All statuses are OK.
The Identity Collector is showing log-on and log-off events from this identity source. 

Following the documentation, we have configured an Identity Tag with the identifier field as an exact match with the SGT's name and used this Identity Tag in an Access Role. We have found an article mentioning a SGT_ prefix is needed when naming the Access Role where the part after the prefix must match the SGT's name. Created an access rule with this role and pushed policy.

When running the 'pdp monitor ip x.x.x.x' command, we can see the security gateway has learned the object and the SGT is shown in the output. But the Access Role remains empty so the access rule is not hit.

Disconnecting the device from the network shows a log-off event in SmartLog and connecting the device to the network shows a log-on event in SmartLog with the correct SGT name, but without a Access Role assigned.

The configuration we have created is done by putting information from different documents and SK articles together. 

What am I missing here?

Has anyone has configured this before?

Tips and tricks would be appreciated.

Regards,
Martijn

 

0 Kudos
1 Solution

Accepted Solutions
Martijn
MVP Platinum
MVP Platinum

Hi,

This solution was simple.

The tag for the printer was configured in the User section of the Access Role. Because the IDC is seeing a machine, the Access Role was not used.

Configured the tag in the Machine section of the Access Role and it worked.

Martijn

View solution in original post

7 Replies
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

Apply some caution here but it's worth reviewing the following as relevant to this environment:

pdp idc groups_consolidation status | enable | disabled

CCSM R77/R80/ELITE
0 Kudos
Martijn
MVP Platinum
MVP Platinum

Chris,

We also checked this one and the setting was enabled.

Martijn

0 Kudos
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

Don't know the specifics of this environment but I've disabled it in the past for other SGT based deployments.

CCSM R77/R80/ELITE
0 Kudos
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

Is this VSX by chance? I remember why it was familiar...

In my previous case the CLI status command showed contradictory information until it was changed from the default value (since fixed).

CCSM R77/R80/ELITE
0 Kudos
fmartensson
Participant

Hi Martijn, did you find a solution to this?

I'm in the same boat, in "pdp monitor ip x.x.x.x" I can see the SGT and it's correspondent access role

In ia_ise_extension.log I can see the session with my IP and it says SecurityGroups (CSGT-<ISE-group>). I have created an user group in SmartConsole with this name, inside an access-role with the name SGT_<ISE-group>, according to the Check Point and ISE Intergration White Paper. 

But I get no hits on my rule

 

Edit: I got it working by making an Identity Tag inside the access-rule. Access-rule name: SGT_xxx, identity tag name: CSGT-xxx, and the external identifier inside the identity tag is the SGT name. This was put under machine groups in the access role 

0 Kudos
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP


@Martijn What was the outcome here?

CCSM R77/R80/ELITE
0 Kudos
Martijn
MVP Platinum
MVP Platinum

Hi,

This solution was simple.

The tag for the printer was configured in the User section of the Access Role. Because the IDC is seeing a machine, the Access Role was not used.

Configured the tag in the Machine section of the Access Role and it worked.

Martijn

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events