<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Access Roles not synced in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-not-synced/m-p/176883#M32406</link>
    <description>&lt;P&gt;update:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The access role is succesfully synced over to the PEP gateway, so that is good.&lt;/P&gt;&lt;P&gt;However, why would it take 48 hours in order for this to sync properly?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 31 Mar 2023 10:58:59 GMT</pubDate>
    <dc:creator>KM1895</dc:creator>
    <dc:date>2023-03-31T10:58:59Z</dc:date>
    <item>
      <title>Access Roles not synced</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-not-synced/m-p/176710#M32387</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;I have come across a bit of a challenge with identity Awareness.&lt;/P&gt;&lt;P&gt;We are using Identity Collector and identity sharing, with 4 gatewas acting as PDP, and several others as PEP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A new access role was recently created, with access rule on a PEP gateway. this is currently in test, and will be moved to production if successful&lt;/P&gt;&lt;P&gt;For one user, this works just fine, and he gets the correct access.&lt;/P&gt;&lt;P&gt;For other users, they do not hit this access rule at all.&lt;/P&gt;&lt;P&gt;When i run a pep show user query usr &amp;lt;username&amp;gt;, i see that the new access role is not associated with the user at all.&lt;/P&gt;&lt;P&gt;Have tried running the pdp sync and pdp update on the PDP gateway closest to the PEP gateway, but the new access role is not associated at all with the user.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this because of the cache on the PDP gateway, as the users will log on again before the 24 hours expire, thus the cached identity is reused?&amp;nbsp;&lt;/P&gt;&lt;P&gt;What would be a potential consequence if we reduce the time limit on the cache before entries are deleted?&lt;/P&gt;&lt;P&gt;The environment is R81.10 with jumbo t66 on top, and there are only appliances in the environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any input here would be appreciated:)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 09:43:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-not-synced/m-p/176710#M32387</guid>
      <dc:creator>KM1895</dc:creator>
      <dc:date>2023-03-30T09:43:35Z</dc:date>
    </item>
    <item>
      <title>Re: Access Roles not synced</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-not-synced/m-p/176825#M32388</link>
      <description>&lt;P&gt;Is the Access Role in use in any policy on the other gateways?&lt;BR /&gt;Not sure how the PDP on the remote gateways will handle roles it does not have any rules for.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This might require a TAC case to get to the bottom of.&lt;BR /&gt;&lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2023 03:01:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-not-synced/m-p/176825#M32388</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-03-31T03:01:27Z</dc:date>
    </item>
    <item>
      <title>Re: Access Roles not synced</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-not-synced/m-p/176844#M32393</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I actually didnt check. The pdp and pep gateways are actually connected( they are the internal and external cluster for the customer),&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, it could be that the access rule is not set on the PDP gateway? But is that a requirement in order for the access rule to work on the PEP gateway? if so, i can check this, and copy the rule over if necessary.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2023 07:13:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-not-synced/m-p/176844#M32393</guid>
      <dc:creator>KM1895</dc:creator>
      <dc:date>2023-03-31T07:13:42Z</dc:date>
    </item>
    <item>
      <title>Re: Access Roles not synced</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-not-synced/m-p/176883#M32406</link>
      <description>&lt;P&gt;update:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The access role is succesfully synced over to the PEP gateway, so that is good.&lt;/P&gt;&lt;P&gt;However, why would it take 48 hours in order for this to sync properly?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2023 10:58:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-not-synced/m-p/176883#M32406</guid>
      <dc:creator>KM1895</dc:creator>
      <dc:date>2023-03-31T10:58:59Z</dc:date>
    </item>
    <item>
      <title>Re: Access Roles not synced</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-not-synced/m-p/176948#M32428</link>
      <description>&lt;P&gt;That's unusual.&lt;BR /&gt;Recommend a TAC case to investigate: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2023 22:22:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-not-synced/m-p/176948#M32428</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-03-31T22:22:07Z</dc:date>
    </item>
    <item>
      <title>Re: Access Roles not synced</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-not-synced/m-p/221912#M42534</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;we are facing similiar problem, did you fix it?&lt;/P&gt;
&lt;P&gt;an access role in a pep gateway is working only from some users (same vlan, same domain), other user are not synced from PDP gateway, where the identity is corrected associated&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 14:00:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-not-synced/m-p/221912#M42534</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2024-07-25T14:00:30Z</dc:date>
    </item>
    <item>
      <title>Re: Access Roles not synced</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-not-synced/m-p/221928#M42541</link>
      <description>&lt;P&gt;Maybe this is related? TAC gave us this for similar issue with a customer...&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk181429" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk181429&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 16:53:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-not-synced/m-p/221928#M42541</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-25T16:53:55Z</dc:date>
    </item>
    <item>
      <title>Re: Access Roles not synced</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-not-synced/m-p/221940#M42542</link>
      <description>&lt;P&gt;thanks Andy,&lt;/P&gt;
&lt;P&gt;no, on pdp gateway the identity is ok&lt;/P&gt;
&lt;P&gt;TAC Case araised&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 17:48:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-not-synced/m-p/221940#M42542</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2024-07-25T17:48:29Z</dc:date>
    </item>
    <item>
      <title>Re: Access Roles not synced</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-not-synced/m-p/221941#M42543</link>
      <description>&lt;P&gt;Let us know what they say.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 17:49:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Access-Roles-not-synced/m-p/221941#M42543</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-25T17:49:31Z</dc:date>
    </item>
  </channel>
</rss>

