> Source: [sk184934](https://support.checkpoint.com/results/sk/sk184934)

# sk184934 - OpenLDAP and other non-Microsoft Active Directory users and groups do not appear in the user / group list in Identity Awareness Access Roles

| Property | Value |
|----------|-------|
| Solution ID | sk184934 |
| Date Created | 2026-05-06 |
| Last Modified | 2026-05-11 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20, R81.10 (EOS) |
| OS | Gaia |

## Symptoms

- * When integrating OpenLDAP (slapd 2.5.x) with Identity Awareness in SmartConsole, the LDAP Account Unit is created successfully. However, in Access Roles, when the Microsoft_AD profile selected, the LDAP tree structure (OUs) is visible, but no users or groups are displayed.

* These error messages may appear:

  * `AD server does not support Virtual List View (VLV)`
  * `AD server does not support Virtual List Sorting`
* When using other directory profiles (for example, NetScape_DS or OPSEC_DS), the directory structure, users, and groups are not displayed.

* Enabling VLV and Server?Side Sorting (SSS/VLS) on the OpenLDAP server removes the error messages, but users and groups still do not appear in the Access Role \> specific users/groups list.

## Cause

The Access Role specific users/groups list is implemented to work only with LDAP Account Units that use the Microsoft_AD profile and connect to Microsoft Active Directory. The list relies on Active Directory--specific LDAP controls, attributes, and schema behavior that are not provided by OpenLDAP directories.

As a result, OpenLDAP cannot be used as a supported identity source for the Access Role user and group GUI list, even when Virtual List View (VLV) and Server?Side Sorting / Virtual List Sorting (SSS/VLS)are enabled.

## Solution

There are two options to resolve this issue.

### **Option 1 - Use legacy LDAP groups with OpenLDAP**

You can use OpenLDAP for group?based policy enforcement, including Remote Access VPN, by using legacy LDAP group objects.

**Step 1 - Verify the LDAP Account Unit**

1. In SmartConsole,confirm that an LDAP Account Unit exists for the OpenLDAP server.
2. Verify that the Base DN, branches, and bind credentials are correct.

**Step 2 - Create legacy LDAP group objects**

1. In SmartConsole, open **Objects** \> **More object types** \> **User/Identity.**
2. Create LDAP Group objects that reference the OpenLDAP Account Unit.
3. Configure the correct Group Distinguished Name (DN) for each group.
4. Save and install the policy.

**Step 3 - Use LDAP groups in Access Roles**

1. In an Access Role, open the **Users** tab.
2. Select the legacy LDAP groups under **LDAP Groups**.
3. Install the Access Control policy.

Note - This method supports group?based access control only. It does not provide per?user or per?host granularity equivalent to Active Directory--based Access Roles.

### **Option 2 - Use Microsoft Active Directory**

For full Access Role functionality, including per?user and per?host selection with the GUI user/group list, use Microsoft Active Directory as the identity source.

**Best Practice**

* Use Microsoft Active Directory when fine?grained per-user and per-host Access Roles are required.
* Use OpenLDAP with legacy LDAP groups when group?based access control is sufficient.
* Per?user Access Roles based on OpenLDAP are not supported.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
