> Source: [sk185085](https://support.checkpoint.com/results/sk/sk185085)

# sk185085 - Gaia Role-Based Administration rejects valid all-Virtual System access configurations in VSX

| Property | Value |
|----------|-------|
| Solution ID | sk185085 |
| Date Created | 2026-06-23 |
| Last Modified | 2026-08-25 |
| Technical Level | Advanced |
| Products | Security Gateway, Scalable Platforms |
| Versions | R82.10, R82, R82.10, R82 |
| OS | Gaia |
| Platform | VMWare ESX, Open Server |

## Symptoms

- * When you try to create a new role with limited permissions and assign access to specific Virtual Systems (VSs), the configuration cannot be saved.  

  The issue affects VSX traditional and VSNext environments that use Gaia Role-Based Administration roles, including local users.

* The failure occurs when the role also includes global features, such as Backup, Expert mode, Configuration, User Management, or Role-Based Administration.  

  Example error in Clish:  

  `Error : NMSRBA0419`  
  `
  NMSRBA0429: features are restricted to global users only and cannot be added to roles with specific VS access.`

* Adding Virtual System (VS) access to a Role-Based Administration (RBA) role fails in Gaia Portal and in the Command Line Interface (CLI).

* When users with RBA role try to log in to a VS, they receive an error:  

  `CLINFR0220: User is not allowed to access any virtual-system.`

* Saving a role with global features in Gaia Portal fails when all Virtual Systems are selected individually rather than using the "Any VS" option.

* Adding global features to a role that already has access to all Virtual Systems fails with an error that refers to limited Virtual System access.

* In Gaia Portal, saving a role can fail with a generic action error.

## Cause

Starting in R82, Gaia Role-Based Administration requires this separation:

* Roles assigned to specific Virtual Systems cannot include Administrator-level features.
* Roles with Administrator-level features must have global (all VS) access.

In the affected scenario, the system does not correctly evaluate all Virtual Systems access during user authentication and role validation. As a result, a valid role configuration can behave as if it has restricted Virtual System access.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
