Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
biskit
Advisor
Advisor
Jump to solution

Access Role not working?

I suspect I'm missing something obvious, so I'm after some help please.

I've set up remote access using Azure AD auth (Identity Provider) - both for Mobile Access (with SNX) and client VPN.  Both authenticate fine and I get an Office Mode IP.  Great.

I've configured an Access Role where I've specified certain users from Azure AD.  When I click "add" it browses Azure AD with no problem, and I select the users I want.

The Access Role is in a rule allowing access to the LAN.

But it doesn't work.  It's as if nothing is being picked up on that Access Role rule.  Traffic is dropped on the cleanup.

If I add a rule lower down to allow the Office Mode net to get to the LAN, then my traffic works on that rule.

I can't work out why my traffic isn't allowed on the Access Role rule which has my Azure name in it?   Obviously I don't want to leave the Office Mode rule in otherwise I have no way of creating rules based on the person.  I presumed Access Roles should do this but they are being completely ignored 😞

I've tried with and without Remote Access in the VPN column, and also tried with Captive Portal in the Accept column.  No difference...

Does anyone have any ideas please?! 

0 Kudos
1 Solution

Accepted Solutions
This widget could not be displayed.
12 Replies
This widget could not be displayed.

With some help from TAC I got it working.  The current instructions from CP don't quite give the full story, so I've attached some notes to supplement and clarify some steps.  The golden rule is - don't miss any steps in SK172909, and don't miss any steps in my attached supplementary notes which fill in some critical gaps in SK172909.

If anyone finds a different/simpler way to achieve this I'd love to know 🙂

View solution in original post

With some help from TAC I got it working.  The current instructions from CP don't quite give the full story, so I've attached some notes to supplement and clarify some steps.  The golden rule is - don't miss any steps in SK172909, and don't miss any steps in my attached supplementary notes which fill in some critical gaps in SK172909.

If anyone finds a different/simpler way to achieve this I'd love to know 🙂

View solution in original post

With some help from TAC I got it working.  The current instructions from CP don't quite give the full story, so I've attached some notes to supplement and clarify some steps.  The golden rule is - don't miss any steps in SK172909, and don't miss any steps in my attached supplementary notes which fill in some critical gaps in SK172909.

If anyone finds a different/simpler way to achieve this I'd love to know 🙂

View solution in original post

With some help from TAC I got it working.  The current instructions from CP don't quite give the full story, so I've attached some notes to supplement and clarify some steps.  The golden rule is - don't miss any steps in SK172909, and don't miss any steps in my attached supplementary notes which fill in some critical gaps in SK172909.

If anyone finds a different/simpler way to achieve this I'd love to know 🙂

View solution in original post

the_rock
MVP Diamond
MVP Diamond
the_rock
MVP Diamond
MVP Diamond
the_rock
MVP Diamond
MVP Diamond

I really wish I could give you logical answer, but I dont know at this point. I would do IA debugs and see if we can pin point a reason. I will find the debugs TAC sent me once and send them to you here.

Andy

Best,
Andy
"Have a great day and if its not, change it"

I really wish I could give you logical answer, but I dont know at this point. I would do IA debugs and see if we can pin point a reason. I will find the debugs TAC sent me once and send them to you here.

Andy

Best,
Andy
"Have a great day and if its not, change it"

I really wish I could give you logical answer, but I dont know at this point. I would do IA debugs and see if we can pin point a reason. I will find the debugs TAC sent me once and send them to you here.

Andy

Best,
Andy
"Have a great day and if its not, change it"
biskit
Advisor
Advisor
biskit
Advisor
Advisor
biskit
Advisor
Advisor

Thanks Andy.  I take a bit of comfort in the knowledge I'm not doing anything completely obviously wrong at this stage?!

Thanks Andy.  I take a bit of comfort in the knowledge I'm not doing anything completely obviously wrong at this stage?!

Thanks Andy.  I take a bit of comfort in the knowledge I'm not doing anything completely obviously wrong at this stage?!

0 Kudos
0 Kudos
0 Kudos
the_rock
MVP Diamond
MVP Diamond
the_rock
MVP Diamond
MVP Diamond
the_rock
MVP Diamond
MVP Diamond

Do you have time for remote session? I think we spoke once before during COVID, you are in UK if I recall? If so, if you are free at say 2 pm your time, just message me privately and we can do remote...I have some ideas.

Andy

Best,
Andy
"Have a great day and if its not, change it"

Do you have time for remote session? I think we spoke once before during COVID, you are in UK if I recall? If so, if you are free at say 2 pm your time, just message me privately and we can do remote...I have some ideas.

Andy

Best,
Andy
"Have a great day and if its not, change it"

Do you have time for remote session? I think we spoke once before during COVID, you are in UK if I recall? If so, if you are free at say 2 pm your time, just message me privately and we can do remote...I have some ideas.

Andy

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
0 Kudos
0 Kudos
RS_Daniel
Advisor
Advisor
RS_Daniel
Advisor
Advisor
RS_Daniel
Advisor
Advisor

Hi,

On the gateway object, identity awareness tab, is "Remote Access" option checked on the list of Identity Sources? after the vpn client connects to the gateway, check if the firewall has any identity related to that IP "pdp monitor ip X.X.X.X" or "pep show user all | grep X.X.X.X"

Regards

Hi,

On the gateway object, identity awareness tab, is "Remote Access" option checked on the list of Identity Sources? after the vpn client connects to the gateway, check if the firewall has any identity related to that IP "pdp monitor ip X.X.X.X" or "pep show user all | grep X.X.X.X"

Regards

Hi,

On the gateway object, identity awareness tab, is "Remote Access" option checked on the list of Identity Sources? after the vpn client connects to the gateway, check if the firewall has any identity related to that IP "pdp monitor ip X.X.X.X" or "pep show user all | grep X.X.X.X"

Regards

the_rock
MVP Diamond
MVP Diamond
the_rock
MVP Diamond
MVP Diamond
the_rock
MVP Diamond
MVP Diamond

Forgot that part about remote access, good point.

Best,
Andy
"Have a great day and if its not, change it"

Forgot that part about remote access, good point.

Best,
Andy
"Have a great day and if its not, change it"

Forgot that part about remote access, good point.

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
0 Kudos
0 Kudos
biskit
Advisor
Advisor
biskit
Advisor
Advisor
biskit
Advisor
Advisor

With some help from TAC I got it working.  The current instructions from CP don't quite give the full story, so I've attached some notes to supplement and clarify some steps.  The golden rule is - don't miss any steps in SK172909, and don't miss any steps in my attached supplementary notes which fill in some critical gaps in SK172909.

If anyone finds a different/simpler way to achieve this I'd love to know 🙂

With some help from TAC I got it working.  The current instructions from CP don't quite give the full story, so I've attached some notes to supplement and clarify some steps.  The golden rule is - don't miss any steps in SK172909, and don't miss any steps in my attached supplementary notes which fill in some critical gaps in SK172909.

If anyone finds a different/simpler way to achieve this I'd love to know 🙂

With some help from TAC I got it working.  The current instructions from CP don't quite give the full story, so I've attached some notes to supplement and clarify some steps.  The golden rule is - don't miss any steps in SK172909, and don't miss any steps in my attached supplementary notes which fill in some critical gaps in SK172909.

If anyone finds a different/simpler way to achieve this I'd love to know 🙂

the_rock
MVP Diamond
MVP Diamond
the_rock
MVP Diamond
MVP Diamond
the_rock
MVP Diamond
MVP Diamond

Amazing job Matt, thanks for that!

Andy

Best,
Andy
"Have a great day and if its not, change it"

Amazing job Matt, thanks for that!

Andy

Best,
Andy
"Have a great day and if its not, change it"

Amazing job Matt, thanks for that!

Andy

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
0 Kudos
0 Kudos
AK2
Collaborator
AK2
Collaborator
AK2
Collaborator

Thanks - I needed to follow your AAD instructions to get matches on my AAD Identity Awareness policies. Much appreciated 🙂

Thanks - I needed to follow your AAD instructions to get matches on my AAD Identity Awareness policies. Much appreciated 🙂

Thanks - I needed to follow your AAD instructions to get matches on my AAD Identity Awareness policies. Much appreciated 🙂

0 Kudos
0 Kudos
0 Kudos
TRajkumar
Contributor
Contributor
TRajkumar
Contributor
Contributor
TRajkumar
Contributor
Contributor

Hello biskit

     Detto i'm facing the same issue. But now i'm trying this on my trial Azure AD (Groups is not possible) and using users. Could you please help me with more details.

Hello biskit

     Detto i'm facing the same issue. But now i'm trying this on my trial Azure AD (Groups is not possible) and using users. Could you please help me with more details.

Hello biskit

     Detto i'm facing the same issue. But now i'm trying this on my trial Azure AD (Groups is not possible) and using users. Could you please help me with more details.

0 Kudos
0 Kudos
0 Kudos
TRajkumar
Contributor
Contributor
TRajkumar
Contributor
Contributor
TRajkumar
Contributor
Contributor

Hi Biskit

  I also facing the same challenge, But in my case i'm using the cloudguard gateways (GCP). I tried the document you have shared but no luck for me. Cloud you please help me to resolve this.

Hi Biskit

  I also facing the same challenge, But in my case i'm using the cloudguard gateways (GCP). I tried the document you have shared but no luck for me. Cloud you please help me to resolve this.

Hi Biskit

  I also facing the same challenge, But in my case i'm using the cloudguard gateways (GCP). I tried the document you have shared but no luck for me. Cloud you please help me to resolve this.

0 Kudos
0 Kudos
0 Kudos