<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Collectors and pdp/pep in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collectors-and-pdp-pep/m-p/200433#M37614</link>
    <description>&lt;P&gt;So, unfortunately it still doesn't work...&lt;/P&gt;&lt;P&gt;It registers when someone logs on to a client as seen below, however, not "regular" events:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fw3.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23642iABE435CE5C78108F/image-size/large?v=v2&amp;amp;px=999" role="button" title="fw3.png" alt="fw3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;But the IDC is both getting events from the AD and sending to the FW GW:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fw4.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23643iA8B944579BBB381E/image-size/large?v=v2&amp;amp;px=999" role="button" title="fw4.png" alt="fw4.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dw5.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23644i77E508BE12495600/image-size/large?v=v2&amp;amp;px=999" role="button" title="dw5.png" alt="dw5.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help would be appreciated!!&lt;/P&gt;</description>
    <pubDate>Wed, 13 Dec 2023 10:33:06 GMT</pubDate>
    <dc:creator>JPR</dc:creator>
    <dc:date>2023-12-13T10:33:06Z</dc:date>
    <item>
      <title>Identity Collectors and pdp/pep</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collectors-and-pdp-pep/m-p/200326#M37581</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I've had some issues with our Identity Collectors and have tried to restart the "pdpd" and "pepd" processes with the following commands:&lt;/P&gt;&lt;P&gt;# fw kill pdpd&lt;BR /&gt;# fw kill pepd&lt;/P&gt;&lt;P&gt;They both seem to be running again and the Identity Collectors are receiving events from our AD and sending to the firewall. Also the firewall says that it is connected as you can see below:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fw1.png" style="width: 733px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23620i11D37ED8A25A2505/image-size/large?v=v2&amp;amp;px=999" role="button" title="fw1.png" alt="fw1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;However, when I look in the "Logs &amp;amp; Monitor" in the SmartConsole it doesn't show/register any "Source User Name" as shown below:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fw2.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23621i2E2888D922F31AF3/image-size/large?v=v2&amp;amp;px=999" role="button" title="fw2.png" alt="fw2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;It does occasionally show someone logging in on a client.&lt;/P&gt;&lt;P&gt;I've restarted the services before and it began working again after some time. Is this expected behaviour because of the "Association time-to-live" on the Identity Collectors or something like that?&lt;BR /&gt;And is there a way for me to make it work again now and not just having to wait?&lt;/P&gt;&lt;P&gt;I'm still a bit new to all this so please forgive me if I'm not all to clear in my explanations.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2023 14:38:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collectors-and-pdp-pep/m-p/200326#M37581</guid>
      <dc:creator>JPR</dc:creator>
      <dc:date>2023-12-12T14:38:30Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collectors and pdp/pep</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collectors-and-pdp-pep/m-p/200433#M37614</link>
      <description>&lt;P&gt;So, unfortunately it still doesn't work...&lt;/P&gt;&lt;P&gt;It registers when someone logs on to a client as seen below, however, not "regular" events:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fw3.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23642iABE435CE5C78108F/image-size/large?v=v2&amp;amp;px=999" role="button" title="fw3.png" alt="fw3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;But the IDC is both getting events from the AD and sending to the FW GW:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fw4.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23643iA8B944579BBB381E/image-size/large?v=v2&amp;amp;px=999" role="button" title="fw4.png" alt="fw4.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dw5.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23644i77E508BE12495600/image-size/large?v=v2&amp;amp;px=999" role="button" title="dw5.png" alt="dw5.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help would be appreciated!!&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 10:33:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collectors-and-pdp-pep/m-p/200433#M37614</guid>
      <dc:creator>JPR</dc:creator>
      <dc:date>2023-12-13T10:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collectors and pdp/pep</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collectors-and-pdp-pep/m-p/200442#M37617</link>
      <description>&lt;P&gt;Better contact CP TAC and get this reviewed in RAS - a look into the configuration is necessary to resolve this...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 11:21:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collectors-and-pdp-pep/m-p/200442#M37617</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-12-13T11:21:48Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collectors and pdp/pep</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collectors-and-pdp-pep/m-p/200443#M37618</link>
      <description>&lt;P&gt;Quickest path is probably to review with TAC.&lt;/P&gt;
&lt;P&gt;Which Gateway &amp;amp; IDC version do you use out of interest?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 11:26:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collectors-and-pdp-pep/m-p/200443#M37618</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-12-13T11:26:11Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collectors and pdp/pep</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collectors-and-pdp-pep/m-p/200451#M37623</link>
      <description>&lt;P&gt;It's R81 and the IDCs are build 81.040.0000.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It worked before I did the fw kill pdpd and fw kill pepd, so I'm quite certain it has something to do with that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I do the pdp status show it says there is no PEPs connected:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pdp.png" style="width: 555px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23645iAAD9C646764E1CF1/image-size/large?v=v2&amp;amp;px=999" role="button" title="pdp.png" alt="pdp.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 12:00:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collectors-and-pdp-pep/m-p/200451#M37623</guid>
      <dc:creator>JPR</dc:creator>
      <dc:date>2023-12-13T12:00:43Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collectors and pdp/pep</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collectors-and-pdp-pep/m-p/200487#M37642</link>
      <description>&lt;P&gt;Is it perhaps because it has to rebuild the database after I restarted pdpd/pepd and the FW doesn't get old events/associations?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 13:46:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collectors-and-pdp-pep/m-p/200487#M37642</guid>
      <dc:creator>JPR</dc:creator>
      <dc:date>2023-12-13T13:46:05Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collectors and pdp/pep</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collectors-and-pdp-pep/m-p/200492#M37643</link>
      <description>&lt;P&gt;Which JHF take is applied to the Gateway, there are potentially relevant fixes here in addition to a newer IDC version&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 14:15:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collectors-and-pdp-pep/m-p/200492#M37643</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-12-13T14:15:27Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collectors and pdp/pep</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collectors-and-pdp-pep/m-p/200493#M37644</link>
      <description>&lt;P&gt;It could be, but better to get TAC involved to confirm, as the guys already said.&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 14:18:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collectors-and-pdp-pep/m-p/200493#M37644</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-13T14:18:46Z</dc:date>
    </item>
  </channel>
</rss>

