<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity sharing - how to change modes in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-sharing-how-to-change-modes/m-p/98942#M12446</link>
    <description>&lt;P&gt;Unlikely - documentation says:&lt;/P&gt;
&lt;P class="subheading"&gt;Push Sharing Method&lt;/P&gt;
&lt;P class="tpbodytext"&gt;This method is straight-forward: a PDP publishes each identity when it is acquired to the PEP.&lt;/P&gt;
&lt;P class="note"&gt;&lt;STRONG class="bold"&gt;Note -&lt;/STRONG&gt; It is the only sharing method for the Identity Awareness Security Gateway that runs both as PDP and PEP.&lt;/P&gt;</description>
    <pubDate>Tue, 13 Oct 2020 07:38:23 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2020-10-13T07:38:23Z</dc:date>
    <item>
      <title>Identity sharing - how to change modes</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-sharing-how-to-change-modes/m-p/62906#M12442</link>
      <description>&lt;P&gt;Hello, as per this document:&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_IdentityAwareness_AdminGuide/html_frameset.htm?topic=documents/R80.10/WebAdminGuides/EN/CP_R80.10_IdentityAwareness_AdminGuide/150080" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_IdentityAwareness_AdminGuide/html_frameset.htm?topic=documents/R80.10/WebAdminGuides/EN/CP_R80.10_IdentityAwareness_AdminGuide/150080&lt;/A&gt;&lt;/P&gt;&lt;P&gt;there are two methods for a remote PEP gateway to learn identities, Smart-Pull or Push Sharing. Based on the output of "pdp connections pep" command (and the fact we can only see a handful of entries one one the other cluster) it seems we have smart-pull mode.&lt;/P&gt;&lt;P&gt;I want to change this to push method. We have a second site with an identical cluster and I would like the PEP databases to be synchronised on both. I cannot find anything that tells me how to do this?&lt;/P&gt;&lt;P&gt;(We are R80.20)&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2019 06:12:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-sharing-how-to-change-modes/m-p/62906#M12442</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2019-09-17T06:12:06Z</dc:date>
    </item>
    <item>
      <title>Re: Identity sharing - how to change modes</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-sharing-how-to-change-modes/m-p/62927#M12443</link>
      <description>&lt;P&gt;This has been an old trick in the first days to cope with IA issues - but it is not (or no longer ?) documented in any sk. This is understandable, as that needs a manual GUIDbedit change on SMS, a thing that should never be done without a good reason&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;. Which issues are you experiencing that would justify such a change ?&lt;/P&gt;
&lt;P&gt;Also, this change is for AD Query only, and AD Query is today commonly replaced by Identity collector. For more information, see &lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk44178&amp;amp;partition=General&amp;amp;product=Identity" target="_blank"&gt;sk44178: &lt;STRONG&gt;Identity&lt;/STRONG&gt;Logging - Frequently Asked Questions&lt;/A&gt;,&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk86441&amp;amp;partition=Advanced&amp;amp;product=Identity" target="_blank"&gt;sk86441: &lt;STRONG&gt;ATRG&lt;/STRONG&gt;: &lt;STRONG&gt;Identity&lt;/STRONG&gt;Awareness,&lt;/A&gt;&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108235&amp;amp;partition=General&amp;amp;product=Identity" target="_blank"&gt;sk108235: &lt;STRONG&gt;Identity&lt;/STRONG&gt;Collector - Technical Overview&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk88520&amp;amp;partition=General&amp;amp;product=Identity" target="_blank"&gt;sk88520: Best Practices - &lt;STRONG&gt;Identity&lt;/STRONG&gt;Awareness Large Scale Deployment.&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2019 09:21:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-sharing-how-to-change-modes/m-p/62927#M12443</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-09-17T09:21:34Z</dc:date>
    </item>
    <item>
      <title>Re: Identity sharing - how to change modes</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-sharing-how-to-change-modes/m-p/62998#M12444</link>
      <description>&lt;P&gt;Hi thanks for the reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes I suspected it was a Dbedit under the hood somewhere.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We did have an issue where an ADquery fetched user was showing on one gateway but not on another where an IA rule was used and therefore the users access was not working. It took me a while to understand why so few users where showing on my other shared cluster compared to the cluster doing ADQuery. That issue however has now self resolved.&lt;/P&gt;&lt;P&gt;So really no reason for us to change mode now - other to to simplify troubleshooting a bit, I still don't fully understand how the smart decides what to pull and what not to pull but I can live with that &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2019 00:38:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-sharing-how-to-change-modes/m-p/62998#M12444</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2019-09-18T00:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: Identity sharing - how to change modes</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-sharing-how-to-change-modes/m-p/98939#M12445</link>
      <description>&lt;P&gt;from what i understand from TAC, Push method is not supported by R&amp;amp;D that is why the configuration is not open for all users.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 07:28:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-sharing-how-to-change-modes/m-p/98939#M12445</guid>
      <dc:creator>Dor_Marcovitch</dc:creator>
      <dc:date>2020-10-13T07:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: Identity sharing - how to change modes</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-sharing-how-to-change-modes/m-p/98942#M12446</link>
      <description>&lt;P&gt;Unlikely - documentation says:&lt;/P&gt;
&lt;P class="subheading"&gt;Push Sharing Method&lt;/P&gt;
&lt;P class="tpbodytext"&gt;This method is straight-forward: a PDP publishes each identity when it is acquired to the PEP.&lt;/P&gt;
&lt;P class="note"&gt;&lt;STRONG class="bold"&gt;Note -&lt;/STRONG&gt; It is the only sharing method for the Identity Awareness Security Gateway that runs both as PDP and PEP.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 07:38:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-sharing-how-to-change-modes/m-p/98942#M12446</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-10-13T07:38:23Z</dc:date>
    </item>
  </channel>
</rss>

