Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
TronNQ
Participant

Understand some cases of Access Role better

Dear Guy!

I am configuring an Access Role for VPN Remote Access related usage.

Specifically, with Access Role there will be 4 data fields is: Networks, Users, Machines, Remote Access Clients.

Let's say I configure a Role with values.

Networks: Any

Users: User local on Checkpoint

Machines: Machine On LDAP

Remote Access Clients: Any

So if I VPN in with a user that matches the user field but the Machines are different, can I access the data according to the rule?

 

0 Kudos
3 Replies
_Val_
Admin
Admin

No. In your case, you are locking access for specific machines only. Clients who can authenticate but not on those specific machines, or when their machine identity cannot be checked, will not be matched to the rule

 

0 Kudos
TronNQ
Participant

So does that mean, if we use machines for Access then we only need specific machines only. And the other values ​​not change?

0 Kudos
PhoneBoy
Admin
Admin

Correct.
Note that we only acquire identities when a user generates a login event.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events