- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi team,
I need your help on this matter.
Here is the environment
We are using MS Active Directory Integration with Access Mobile Access and we defined access role.
But, AD users not belonging to an access role have access to mobile access portal, why ? In the log we see in the usergroup_-"user do not belong to any group".
I want to know if this is an expected behaviour ? from my understanding, an Access Role is how the firewall determines what users are allowed access and those that are not define will be dropped.
Regards
Ok, looks like expected behaviour.
If the gateway is member of the remote access community and the "participant user groups" ist set to "all users" this is working as designed.
The users can authenticate but have no access to any MOB application or VPN connection.
If you want to limit to a specific usergroup you have to define them and replace the "all users". If you don't use any remote-access VPN on your gateway (SSL extender, checkpoint mobile etc.) you can remove the gateway from the remote access community.
Wolfgang
Wolfgang
It may be depending on how you've configured it.
Screenshots of the relevant configuration would be helpful.
Hi PhoneBoy,
Thank for your reply.
This is a basic configuration in R80.40 ( I have the same behavior in my lab R80.10)
- 2 Access roles
- 2 rules with the both access roles in the source and mobile access application
I have attached screenshots
Regards
are the users with no group-mebership able to login only and did not see any MOB-defined application ?
Wolfgang
Hi,
The users with no group-membership are able to login only and they did not see any MOB-defined application,
Regards
Ok, looks like expected behaviour.
If the gateway is member of the remote access community and the "participant user groups" ist set to "all users" this is working as designed.
The users can authenticate but have no access to any MOB application or VPN connection.
If you want to limit to a specific usergroup you have to define them and replace the "all users". If you don't use any remote-access VPN on your gateway (SSL extender, checkpoint mobile etc.) you can remove the gateway from the remote access community.
Wolfgang
Wolfgang
Thank for your help on this matter.
To sum up, as we cannot select Access Roles, the following procedure is relevant
1) Create a ldap group that containt the AD users allowed
2) Then, select the previous ldap group in the remote access community
Regards
Hi Wolfgang,
Thank for your help on this matter: that solved my issue!
Regards
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
15 | |
12 | |
8 | |
6 | |
6 | |
6 | |
5 | |
5 | |
4 | |
3 |
Tue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY