- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Good day;
Hope all is well, I have a quick question is there a way from the firewall that I can pull a specific group defined in Active Directory and import that group to the firewall so I can create a policy from the AD group? What I am trying to accomplish is that every time the AD group is updated that the same group on the firewall will poll any changes from the AD and update its user group or is that wishful thinking and all this has to be done manually. So if someone new joins the company and AD gets updated I will have to go to the firewall and update that new person for access as well? I hope that make sense.
Thank you in advance!!!
Warren
You dont have to do that, its all automatic. TAC told me once that sometimes it may take up to 15 mins, but I fins its way faster than that. Also, if you wish to use certain AD group, that can be done by creating access role, which you need identity awareness blade enabled on the fw.
Best,
Andy
Really?!?! Perhaps I am not looking correctly but is there instructions on how to do that? I didn't find any so that is why I asked here.
No clue what instructions those are, if you can send, happy to check. Personally, I never ever had to do anything for it.
Best,
Andy
Thats the thing, not sure how to start, I was just going to do it manually and add/remove folks as needed but then someone asked isn't there a way you can base it off an AD group and have the firewall pull it from there. I was hoping someone already done so and can point me in the right direction or point me to the documentation. If not, I will just do it manually
Here is what I would personally suggest...if you have to do this manually, something else is wrong. I would call TAC and do remote session, so they can examine the config. Is this onprem mgmt or S1C? Can you make sure branches can be fetched from ldap account unit? Also, say if you use IA blade, then when creating new access role, users should be able to be pulled from the AD 100% (thats mind you if all was syched right)
Andy
ok thank you sir for the info, will talk to TAC
Thank you Andy for your help!!!
Thank you,
Warren
@gurowar if I understand your requirement correct you simple need to implement Identity Awareness to build a rulebase based on identities. Have look at Enforcing Security Based on Identities to understand how it works and how to build.
Will check it out, thank you sir!!
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 3 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY