- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I am new to identity awareness. I have implemented identity collector with AD and LDAP connectivity from the GWs. I have an existing network rule that has normal source / destination hosts and network objects in them. I added an access role to the 'destination' column, and the policy verification fails stating " 'Destination' column of the rule contains both Access Roles and network objects".
1. Why can't network objects and access roles co-exist in the same column?
2. What is the best practice for deploying these rules? Do I have to create an identical rule with the source / services, and put just the access role in for the destination?
R80.20 / JHFA 87
thanks,
Phil
Unfortunately, I do not know the answer to #1.
But in regards to #2, when I haven't been able to just fully replace the src/dst with an Access Role, I usually just put another rule above the existing one with just the Access Role in place of the src/dst object. It is a little clunky, but it seems to be the only way to get around the issue.
It appears this was not addressed in R80.40. Do you know if this was changed in R81?
@Royi_Priov did we ever address this limitation?
Hi @phlrnnr ,
No, there is no plan to address it - the logic behind this decision is indeed in the same area as Kaspars wrote above.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 16 | |
| 15 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY