Security Policy & Identity Awareness
The rule is right and the identity is missing. Follow the identity from the domain controller to the gateway, live, right below.
Symptom
Ordered policy layers, NAT rules and Identity Awareness on a Gaia gateway managed from SmartConsole.
Your mission
Inspect, recover, then verify
Format
Gaia expert-mode CLI
Investigate before you configure.
Use the CLI evidence to isolate the fault, make the smallest safe correction, then verify the network state changed.
Observe the symptom and link state.
Diagnose by comparing the protocol evidence.
Verify the expected device state and confirm the original symptom is resolved.
Console access: Gaia gateway
This workspace stacks for portrait phones. Rotate to landscape for the full split-screen console.
Need a hint?
Reveal the root cause when you're ready.
Try the investigation first, then use this as your escape hatch, not a dead end.
Lab debrief
Turn the session into a repeatable troubleshooting pattern.
Use this reference after your attempt: first explain the symptom, then verify the evidence, then confirm the repair.
The problem
A user-based security rule should match a specific logged-in user, but their traffic keeps hitting a fallback rule instead, as if Check Point doesn't know who they are.
What you'll practice
- Build ordered security policy layers in SmartConsole
- Configure NAT rules on a Gaia gateway
- Enable and test Identity Awareness for user-based policy
- Push policy from the management server to the gateway
- Read SmartConsole logs to verify policy hits
The topology
A Gaia security gateway managed from a SmartConsole management server, with hosts on both sides, the standard Check Point management/gateway split you'll work with in any real deployment.
Commands to run yourself
The real diagnostic commands for this lab, copy-paste ready. Run these in the same order to reproduce the investigation on your own session.
pdp monitor ip 10.20.30.44pdp monitor alladlog a dcTopology diagram
Fact-checked references
The commands and behaviour in this lab were checked against these primary references.
Frequently asked
Do I need a Check Point license to use this lab?
No. The management server and gateway are already licensed and paired. You build policy, not infrastructure.
Does this cover CCSE-level topics?
Layered policy, NAT and Identity Awareness are core CCSE topics. This lab is scoped to practice them hands-on.
Ready to run this lab yourself?
No setup, no image sourcing. Book a session or ask for a live demo.