sk181429 - When a user changes AD group, their access role is not updated

When a user changes AD group, their access role is not updated

Product: Identity Awareness
Version: R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20
OS: Gaia
Platform: All
Last Modified: 2024-04-29

Symptoms

[vpnd 22266 4074710976]@l909eoaa0102a[28 Feb 15:52:21][CPLDAPSDK] ldap_async_do_search: Error: ldap_search_ext
[vpnd 22266 4074710976]@l909eoaa0102a[28 Feb 15:52:21][CPLDAPSDK] OPSEC_ldap_search: do search failure

Cause

When changing the AD user group, the PDP does not update the access roles.

Solution

This problem was fixed. The fix is included starting from:

After installing fix PRHF-28702 the following steps are needed -

To enable, Check Point Security Gateway, run:

# ckp_regedit -a SOFTWARE/CheckPoint/VPN1 use_only_identity_provider_groups -n 1
install policy
To disable, Check Point Security Gateway, run:

# ckp_regedit -d SOFTWARE/CheckPoint/VPN1 use_only_identity_provider_groups
install policy
To view, run:

# ckp_regedit -p SOFTWARE/CheckPoint/VPN1

Check Point recommends to always upgrade to the Recommended version (Security Gateway / VSX / Security Management Server / Multi-Domain Security Management Server / SmartConsole).

If you choose not to upgrade, contact Check Point Support to get a Hotfix for your version.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.