[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[FW-1] External group and policy server logon error.



Hi,

I have defined an external group "MyGroup" from MS Active Directory to use with SecureClient.
I can authenticate against FW, but when trying to log on to policy server, client gives me following error:'
"You are not licensed to obtain a security policy from policy server SRVNAME at site MYFIREWALL."
Error at FW log displays:
"User Username failed to log on to Policy Server. User is not authorized to work with this Policy Server".

Licenses are in place and I also have defined a users group(external "MyGroup")on enforcement point properties, who can access policy server.
Logging on to policy server works only when using FW-1 local groups and users.

Any ideas?
Or external groups are not to work with policy server?


Configuration:
Checkpoint-FW1 NG FP2 @ Sun Solaris8

rgds,
Aigar

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[email protected]
=================================================