<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Awareness - active directory changes / time in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-active-directory-changes-time/m-p/161594#M28625</link>
    <description>&lt;P&gt;Have you implemented: &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk169120&amp;amp;partition=Advanced&amp;amp;product=Identity" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk169120&amp;amp;partition=Advanced&amp;amp;product=Identity&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 08 Nov 2022 15:40:00 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2022-11-08T15:40:00Z</dc:date>
    <item>
      <title>Identity Awareness - active directory changes / time</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-active-directory-changes-time/m-p/161589#M28623</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;I am working with a customer who has an&amp;nbsp;Identity Awareness setup.&lt;/P&gt;&lt;P&gt;I am running 2 collectors on Windows. And a R81.10 cluster with Jumbo take 30.&lt;/P&gt;&lt;P&gt;The customers main complain is that if they make a change in active directory it takes long to be 'active' on the Check Point.&lt;/P&gt;&lt;P&gt;On the Check Point I have a few firewall rules with access roles in it based on a AD group.&lt;/P&gt;&lt;P&gt;The customer adds a new machine(or a user) in the AD group and sees that it is synced to all AD servers. But the rule is not working, after a period of time it starts to work. The customer is wondering if there is any way to speed this up a bit. I noticed sometimes it takes even a few hours. Is there any setting on the gateway or the collector I can change? Or is it random timer?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for the feedback.&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Lesley&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2022 15:12:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-active-directory-changes-time/m-p/161589#M28623</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2022-11-08T15:12:43Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - active directory changes / time</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-active-directory-changes-time/m-p/161594#M28625</link>
      <description>&lt;P&gt;Have you implemented: &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk169120&amp;amp;partition=Advanced&amp;amp;product=Identity" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk169120&amp;amp;partition=Advanced&amp;amp;product=Identity&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2022 15:40:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-active-directory-changes-time/m-p/161594#M28625</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-11-08T15:40:00Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - active directory changes / time</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-active-directory-changes-time/m-p/161597#M28626</link>
      <description>&lt;P&gt;Thank you for the update. Settings was not enabled. I changed it and now we are going to test it. Will get back to you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Expert@FW1:0]# pdp idc groups_update status&lt;BR /&gt;automatic LDAP groups update is disabled&lt;BR /&gt;[Expert@FW1:0]# pdp idc groups_update on&lt;BR /&gt;automatic LDAP groups update is enabled&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2022 15:49:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-active-directory-changes-time/m-p/161597#M28626</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2022-11-08T15:49:42Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - active directory changes / time</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-active-directory-changes-time/m-p/161634#M28636</link>
      <description>&lt;P&gt;Ironically enough, I worked with customer who was doing regular AD query (not identity collector) and they asked me about it, but when we spoke to TAC, they said changes would be instant on CP side. Well, not exactly : - ). We still, to this day, notice that most changes do take effect quick, but I would day about 20% of the time, takes a bit of time.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the other hand, I also work with client who uses 2 IA collectors and they never had this problem, nor did they ever have to implement sk phoneboy mentioned. Maybe its isolated case, I have no clue in the world. All I can say is, I hope the commands help your case.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2022 03:32:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-active-directory-changes-time/m-p/161634#M28636</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-09T03:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - active directory changes / time</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-active-directory-changes-time/m-p/161644#M28644</link>
      <description>&lt;P&gt;Thanks all, customer has tested it today and was way quicker, around 5 minutes.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2022 08:16:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-active-directory-changes-time/m-p/161644#M28644</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2022-11-09T08:16:00Z</dc:date>
    </item>
  </channel>
</rss>

