- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello all,
within an organisation some VPN users are for technicians outside the organisation. They are from
vendors to help in emergencies or to maintain the vendor machines. The requirement is to allow these
users in case of an emergency without to have call an firewall admin to allow the user in the policy.
At the moment I tend to solve this via management API and time objects, it seems for me the best solution.
To have a sub-layer and an admin account with less privileges was another thought. The user properties
looks not so flexible.
This requirement seems not to unusually, so how is this solved by others?
Regards,
Alex
Within a layer you can allow a defined read-only admin user write access without needing the access to any other layer.
That said, you could build a webpage that would be allowed to update that layer with a single click, for instance telling it to allow the user in for the next hour.
If these are contractors another option may simply be to control this at the Active Directory level depending on the specifics?
- Group membership & Identity Rules
- Account Enabled or Disabled
Yes, that was also my thoughts. A webpage with own users and a "backend" wich has the Check Point API user.
At the moment my idea is to have time objects with tags. The tags helps to identify the time objects. The firewall
admin can build the rules needed and give the rules the time objects.
The non firewall user log into a webpage and sees only the time objects he could allow. A click and the time
object will be updated to allow the rule for some hours.
What would be the benefit of layers instead of time objects? At the moment I cannot use layers anyway. But I'm
always happy to hear opinions.
The requirement for such a scenario seems not to specific, perhaps there are other solutions which are I'm
not aware of.
Regards,
Alex
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY