<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IDC events not coming on Firewall in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IDC-events-not-coming-on-Firewall/m-p/241838#M46971</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Yes it is off, since one firewall is working fine.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 20 Feb 2025 18:15:36 GMT</pubDate>
    <dc:creator>ajsingh</dc:creator>
    <dc:date>2025-02-20T18:15:36Z</dc:date>
    <item>
      <title>IDC events not coming on Firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IDC-events-not-coming-on-Firewall/m-p/241821#M46968</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I recently installed IDC on a separate Window server and configured it as per the Guide.&lt;/P&gt;&lt;P&gt;I have connected to 6 of my DC's and its receiving events fine. Then i connected one Firewall which is in the same virtual Network and it is receiving all the events and i see users and Machine identities in my firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;FW (identity source)-----&amp;gt;Identity collector&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now I have added another firewall and it is connected and IDC shows connected and Events are being sent . On firewall, I dont see any user/Machine identities getting updated .&lt;/P&gt;&lt;P&gt;Firewall (Identity source)-----&amp;gt;VPN site to site-----&amp;gt;Identity collector&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there something else I have to do for Events to go over VPN tunnel to my Firewalls that is trying to get identities from IDC ? Because if its is not over VPN tunnel , its working fine.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both Firewalls are R81.20 and have same configuration and IDC shows both connected and events are being sent and I do see numbers increase in IDC.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2025 16:17:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IDC-events-not-coming-on-Firewall/m-p/241821#M46968</guid>
      <dc:creator>ajsingh</dc:creator>
      <dc:date>2025-02-20T16:17:46Z</dc:date>
    </item>
    <item>
      <title>Re: IDC events not coming on Firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IDC-events-not-coming-on-Firewall/m-p/241833#M46969</link>
      <description>&lt;P&gt;Maybe a silly question, but did you make sure windows fw is off on that machine?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2025 17:52:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IDC-events-not-coming-on-Firewall/m-p/241833#M46969</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-20T17:52:54Z</dc:date>
    </item>
    <item>
      <title>Re: IDC events not coming on Firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IDC-events-not-coming-on-Firewall/m-p/241838#M46971</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Yes it is off, since one firewall is working fine.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2025 18:15:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IDC-events-not-coming-on-Firewall/m-p/241838#M46971</guid>
      <dc:creator>ajsingh</dc:creator>
      <dc:date>2025-02-20T18:15:36Z</dc:date>
    </item>
    <item>
      <title>Re: IDC events not coming on Firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IDC-events-not-coming-on-Firewall/m-p/241839#M46972</link>
      <description>&lt;P&gt;K, I see what you meant in your post. So, the one that fails, the difference is it goes over vpn tunnel. Can you do capture and make sire IC ip is not getting dropped? Run fw monitor and then in other ssh window run zdebug&lt;/P&gt;
&lt;P&gt;So say IC ip is 10.10.10.10, do something like this:&lt;/P&gt;
&lt;P&gt;ssh 1 -&amp;gt; fw monitor -e "accept host(10.10.10.10);"&lt;/P&gt;
&lt;P&gt;ssh 2 -&amp;gt; fw ctl zdebug + drop | grep 10.10.10.10&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2025 18:27:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IDC-events-not-coming-on-Firewall/m-p/241839#M46972</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-20T18:27:07Z</dc:date>
    </item>
    <item>
      <title>Re: IDC events not coming on Firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IDC-events-not-coming-on-Firewall/m-p/241841#M46973</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just confirmed that traffic indeed is coming at port 443 and there is no drop in the traffic. I do see vpn logs too and nothing looks out of place. All connectivity looks fine &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2025 18:35:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IDC-events-not-coming-on-Firewall/m-p/241841#M46973</guid>
      <dc:creator>ajsingh</dc:creator>
      <dc:date>2025-02-20T18:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: IDC events not coming on Firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IDC-events-not-coming-on-Firewall/m-p/241844#M46974</link>
      <description>&lt;P&gt;I would try restart IC machine to see if it makes any difference. Maybe also run pdp update all on the problematic gateway.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2025 18:40:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IDC-events-not-coming-on-Firewall/m-p/241844#M46974</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-20T18:40:19Z</dc:date>
    </item>
    <item>
      <title>Re: IDC events not coming on Firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IDC-events-not-coming-on-Firewall/m-p/241850#M46975</link>
      <description>&lt;P&gt;output from my problematic firewall :&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2025 18:53:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IDC-events-not-coming-on-Firewall/m-p/241850#M46975</guid>
      <dc:creator>ajsingh</dc:creator>
      <dc:date>2025-02-20T18:53:48Z</dc:date>
    </item>
    <item>
      <title>Re: IDC events not coming on Firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IDC-events-not-coming-on-Firewall/m-p/241862#M46976</link>
      <description>&lt;P&gt;That 100% looks right to me. I would open TAC case about it to see what they say.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2025 19:27:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IDC-events-not-coming-on-Firewall/m-p/241862#M46976</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-20T19:27:17Z</dc:date>
    </item>
    <item>
      <title>Re: IDC events not coming on Firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IDC-events-not-coming-on-Firewall/m-p/241896#M46977</link>
      <description>&lt;P&gt;One thing I would do is maybe try do IA debugs on the fw and see what gives.&lt;/P&gt;
&lt;P&gt;commands are pep debug on and pdp debug on (off to turn off). Once done, check $FWDIR/dir log for pep and pdp log files.&lt;/P&gt;
&lt;P&gt;Hope that helps.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 00:10:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IDC-events-not-coming-on-Firewall/m-p/241896#M46977</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-21T00:10:35Z</dc:date>
    </item>
    <item>
      <title>Re: IDC events not coming on Firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IDC-events-not-coming-on-Firewall/m-p/241957#M47000</link>
      <description>&lt;P&gt;Thank you all for your replies. am heading for my vacation for next week. I will open tac case now once am back &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 17:30:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IDC-events-not-coming-on-Firewall/m-p/241957#M47000</guid>
      <dc:creator>ajsingh</dc:creator>
      <dc:date>2025-02-21T17:30:26Z</dc:date>
    </item>
    <item>
      <title>Re: IDC events not coming on Firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IDC-events-not-coming-on-Firewall/m-p/241958#M47001</link>
      <description>&lt;P&gt;Have a nice vacation!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 17:46:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IDC-events-not-coming-on-Firewall/m-p/241958#M47001</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-21T17:46:38Z</dc:date>
    </item>
  </channel>
</rss>

