<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Machines in EPG (Cisco ACI) are rebooted but not updated on Gateway in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Machines-in-EPG-Cisco-ACI-are-rebooted-but-not-updated-on/m-p/247928#M48431</link>
    <description>&lt;P&gt;Envirornment:&lt;/P&gt;&lt;P&gt;R81.20 JHF T92 Cluster HA with 2 members.&lt;BR /&gt;Identity Awareness blade with CloudGourd Controller (Cisco ACI).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When servers are rebooted within an EPG on Cisco ACI, traffic is being dropped by the cleanup access rule.&lt;/P&gt;&lt;P&gt;The reason is that it doesn't hit the accessrules where EPG objects are used.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the command #pep show user query cid &amp;lt;ip address of server&amp;gt; doesn't show me the &lt;STRONG&gt;Identity Role&lt;/STRONG&gt; after a reboot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Before the reboot:&lt;/P&gt;&lt;P&gt;[Expert@gateway:0]# pep show user query cid 1.2.3.4&lt;BR /&gt;Command: root-&amp;gt;show-&amp;gt;user-&amp;gt;query&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;PDP: &amp;lt;127.0.0.1, 00000000&amp;gt;; UID: &amp;lt;ee315f18&amp;gt;&lt;BR /&gt;==================================================&lt;BR /&gt;Client ID : &amp;lt;1.2.3.4, 00000000&amp;gt;&lt;BR /&gt;Authentication Key : &amp;lt;Unavailable&amp;gt;&lt;BR /&gt;Brute force counter: 0&lt;BR /&gt;Username :&lt;BR /&gt;Log Username :&lt;BR /&gt;&lt;STRONG&gt;Machine name : epg-workspace&lt;/STRONG&gt;&lt;BR /&gt;User groups : &amp;lt;Unavailable&amp;gt;&lt;BR /&gt;Machine groups : &amp;lt;Unavailable&amp;gt;&lt;BR /&gt;Compliance : &amp;lt;Unavailable&amp;gt;&lt;BR /&gt;I&lt;STRONG&gt;dentity Role : &amp;lt;epg-workspace&amp;gt;&lt;/STRONG&gt;&lt;BR /&gt;Time to live : 604830&lt;BR /&gt;Cached time : 86400&lt;BR /&gt;TTL counter : 0&lt;BR /&gt;Time left : 587914&lt;BR /&gt;&lt;STRONG&gt;Client type : Identity Awareness API&lt;/STRONG&gt;&lt;BR /&gt;Last update time : Thu May 1 10:22:02 2025&lt;/P&gt;&lt;P&gt;Backup Pdps :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After the reboot of server 1.2.3.4 within the EPG group "epg-workspace" on Cisco ACI&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Expert@gateway:0]# pep show user query cid 1.2.3.4&lt;BR /&gt;Command: root-&amp;gt;show-&amp;gt;user-&amp;gt;query&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;PDP: &amp;lt;127.0.0.1, 00000000&amp;gt;; UID: &amp;lt;ee315f18&amp;gt;&lt;BR /&gt;==================================================&lt;BR /&gt;Client ID : &amp;lt;1.2.3.4, 00000000&amp;gt;&lt;BR /&gt;Authentication Key : &amp;lt;Unavailable&amp;gt;&lt;BR /&gt;Brute force counter: 0&lt;BR /&gt;Username :&lt;BR /&gt;Log Username :&lt;BR /&gt;&lt;STRONG&gt;Machine name : servername1&lt;/STRONG&gt;&lt;BR /&gt;User groups : &amp;lt;Unavailable&amp;gt;&lt;BR /&gt;Machine groups : &amp;lt;Unavailable&amp;gt;&lt;BR /&gt;Compliance : &amp;lt;Unavailable&amp;gt;&lt;BR /&gt;&lt;STRONG&gt;Identity Role : &amp;lt;&amp;gt;&lt;/STRONG&gt;&lt;BR /&gt;Time to live : 43230&lt;BR /&gt;Cached time : 86400&lt;BR /&gt;TTL counter : 43170&lt;BR /&gt;Time left : 42650&lt;BR /&gt;&lt;STRONG&gt;Client type : Identity Collector&lt;/STRONG&gt;&lt;BR /&gt;Last update time : Thu May 1 14:44:49 2025&lt;/P&gt;&lt;P&gt;Backup Pdps :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the output above, the IP adddress has been masked by fictitious ip addresses, machine names and identity roles.&lt;/P&gt;&lt;P&gt;Within the SmartConsole -&amp;gt; Data Center Objects the EPG object contains the ip address of the rebooted servers but it has a timestamp behind "Updated on Data Center" of this morning a couple of hours before the reboots.&lt;/P&gt;&lt;P&gt;Why is the gateway not automatically updated with the identity role of the epg-workspace?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Update:&lt;/P&gt;&lt;P&gt;It looks like after a policy install on the gateways, the #pep show user query cid &amp;lt;ip address&amp;gt; is changed and it's working again.&lt;/P&gt;&lt;P&gt;The client type id has also been changed from "Identity Collectors" to "Identity Awareness API".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PDP: &amp;lt;127.0.0.1, 00000000&amp;gt;; UID: &amp;lt;ee315f18&amp;gt;&lt;BR /&gt;==================================================&lt;BR /&gt;Client ID : &amp;lt;1,2,3,4, 00000000&amp;gt;&lt;BR /&gt;Authentication Key : &amp;lt;Unavailable&amp;gt;&lt;BR /&gt;Brute force counter: 0&lt;BR /&gt;Username :&lt;BR /&gt;Log Username :&lt;BR /&gt;Machine name : epg-workspace&lt;BR /&gt;User groups : &amp;lt;Unavailable&amp;gt;&lt;BR /&gt;Machine groups : &amp;lt;Unavailable&amp;gt;&lt;BR /&gt;Compliance : &amp;lt;Unavailable&amp;gt;&lt;BR /&gt;Identity Role : &amp;lt;epg-workspace&amp;gt;&lt;BR /&gt;Time to live : 604830&lt;BR /&gt;Cached time : 86400&lt;BR /&gt;TTL counter : 0&lt;BR /&gt;Time left : 604813&lt;BR /&gt;&lt;STRONG&gt;Client type : Identity Awareness API&lt;/STRONG&gt;&lt;BR /&gt;Last update time : Thu May 1 15:44:52 2025&lt;/P&gt;&lt;P&gt;Backup Pdps :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why isn't this done automatically without a policy installation ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 01 May 2025 13:49:06 GMT</pubDate>
    <dc:creator>RayP</dc:creator>
    <dc:date>2025-05-01T13:49:06Z</dc:date>
    <item>
      <title>Machines in EPG (Cisco ACI) are rebooted but not updated on Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Machines-in-EPG-Cisco-ACI-are-rebooted-but-not-updated-on/m-p/247928#M48431</link>
      <description>&lt;P&gt;Envirornment:&lt;/P&gt;&lt;P&gt;R81.20 JHF T92 Cluster HA with 2 members.&lt;BR /&gt;Identity Awareness blade with CloudGourd Controller (Cisco ACI).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When servers are rebooted within an EPG on Cisco ACI, traffic is being dropped by the cleanup access rule.&lt;/P&gt;&lt;P&gt;The reason is that it doesn't hit the accessrules where EPG objects are used.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the command #pep show user query cid &amp;lt;ip address of server&amp;gt; doesn't show me the &lt;STRONG&gt;Identity Role&lt;/STRONG&gt; after a reboot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Before the reboot:&lt;/P&gt;&lt;P&gt;[Expert@gateway:0]# pep show user query cid 1.2.3.4&lt;BR /&gt;Command: root-&amp;gt;show-&amp;gt;user-&amp;gt;query&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;PDP: &amp;lt;127.0.0.1, 00000000&amp;gt;; UID: &amp;lt;ee315f18&amp;gt;&lt;BR /&gt;==================================================&lt;BR /&gt;Client ID : &amp;lt;1.2.3.4, 00000000&amp;gt;&lt;BR /&gt;Authentication Key : &amp;lt;Unavailable&amp;gt;&lt;BR /&gt;Brute force counter: 0&lt;BR /&gt;Username :&lt;BR /&gt;Log Username :&lt;BR /&gt;&lt;STRONG&gt;Machine name : epg-workspace&lt;/STRONG&gt;&lt;BR /&gt;User groups : &amp;lt;Unavailable&amp;gt;&lt;BR /&gt;Machine groups : &amp;lt;Unavailable&amp;gt;&lt;BR /&gt;Compliance : &amp;lt;Unavailable&amp;gt;&lt;BR /&gt;I&lt;STRONG&gt;dentity Role : &amp;lt;epg-workspace&amp;gt;&lt;/STRONG&gt;&lt;BR /&gt;Time to live : 604830&lt;BR /&gt;Cached time : 86400&lt;BR /&gt;TTL counter : 0&lt;BR /&gt;Time left : 587914&lt;BR /&gt;&lt;STRONG&gt;Client type : Identity Awareness API&lt;/STRONG&gt;&lt;BR /&gt;Last update time : Thu May 1 10:22:02 2025&lt;/P&gt;&lt;P&gt;Backup Pdps :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After the reboot of server 1.2.3.4 within the EPG group "epg-workspace" on Cisco ACI&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Expert@gateway:0]# pep show user query cid 1.2.3.4&lt;BR /&gt;Command: root-&amp;gt;show-&amp;gt;user-&amp;gt;query&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;PDP: &amp;lt;127.0.0.1, 00000000&amp;gt;; UID: &amp;lt;ee315f18&amp;gt;&lt;BR /&gt;==================================================&lt;BR /&gt;Client ID : &amp;lt;1.2.3.4, 00000000&amp;gt;&lt;BR /&gt;Authentication Key : &amp;lt;Unavailable&amp;gt;&lt;BR /&gt;Brute force counter: 0&lt;BR /&gt;Username :&lt;BR /&gt;Log Username :&lt;BR /&gt;&lt;STRONG&gt;Machine name : servername1&lt;/STRONG&gt;&lt;BR /&gt;User groups : &amp;lt;Unavailable&amp;gt;&lt;BR /&gt;Machine groups : &amp;lt;Unavailable&amp;gt;&lt;BR /&gt;Compliance : &amp;lt;Unavailable&amp;gt;&lt;BR /&gt;&lt;STRONG&gt;Identity Role : &amp;lt;&amp;gt;&lt;/STRONG&gt;&lt;BR /&gt;Time to live : 43230&lt;BR /&gt;Cached time : 86400&lt;BR /&gt;TTL counter : 43170&lt;BR /&gt;Time left : 42650&lt;BR /&gt;&lt;STRONG&gt;Client type : Identity Collector&lt;/STRONG&gt;&lt;BR /&gt;Last update time : Thu May 1 14:44:49 2025&lt;/P&gt;&lt;P&gt;Backup Pdps :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the output above, the IP adddress has been masked by fictitious ip addresses, machine names and identity roles.&lt;/P&gt;&lt;P&gt;Within the SmartConsole -&amp;gt; Data Center Objects the EPG object contains the ip address of the rebooted servers but it has a timestamp behind "Updated on Data Center" of this morning a couple of hours before the reboots.&lt;/P&gt;&lt;P&gt;Why is the gateway not automatically updated with the identity role of the epg-workspace?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Update:&lt;/P&gt;&lt;P&gt;It looks like after a policy install on the gateways, the #pep show user query cid &amp;lt;ip address&amp;gt; is changed and it's working again.&lt;/P&gt;&lt;P&gt;The client type id has also been changed from "Identity Collectors" to "Identity Awareness API".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PDP: &amp;lt;127.0.0.1, 00000000&amp;gt;; UID: &amp;lt;ee315f18&amp;gt;&lt;BR /&gt;==================================================&lt;BR /&gt;Client ID : &amp;lt;1,2,3,4, 00000000&amp;gt;&lt;BR /&gt;Authentication Key : &amp;lt;Unavailable&amp;gt;&lt;BR /&gt;Brute force counter: 0&lt;BR /&gt;Username :&lt;BR /&gt;Log Username :&lt;BR /&gt;Machine name : epg-workspace&lt;BR /&gt;User groups : &amp;lt;Unavailable&amp;gt;&lt;BR /&gt;Machine groups : &amp;lt;Unavailable&amp;gt;&lt;BR /&gt;Compliance : &amp;lt;Unavailable&amp;gt;&lt;BR /&gt;Identity Role : &amp;lt;epg-workspace&amp;gt;&lt;BR /&gt;Time to live : 604830&lt;BR /&gt;Cached time : 86400&lt;BR /&gt;TTL counter : 0&lt;BR /&gt;Time left : 604813&lt;BR /&gt;&lt;STRONG&gt;Client type : Identity Awareness API&lt;/STRONG&gt;&lt;BR /&gt;Last update time : Thu May 1 15:44:52 2025&lt;/P&gt;&lt;P&gt;Backup Pdps :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why isn't this done automatically without a policy installation ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 May 2025 13:49:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Machines-in-EPG-Cisco-ACI-are-rebooted-but-not-updated-on/m-p/247928#M48431</guid>
      <dc:creator>RayP</dc:creator>
      <dc:date>2025-05-01T13:49:06Z</dc:date>
    </item>
    <item>
      <title>Re: Machines in EPG (Cisco ACI) are rebooted but not updated on Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Machines-in-EPG-Cisco-ACI-are-rebooted-but-not-updated-on/m-p/247959#M48435</link>
      <description>&lt;P&gt;Hey &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/36329"&gt;@RayP&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Have you checked the cloud_proxy.elg log for any relevant error messages? If you have an SMS, the file should be located in $FWDIR/log. On an MDS it's located in $MDS_FWDIR/log. Might be worth a nose in there. I've experienced similar issues before where the EPG traffic wasn't matching the Cisco ACI object in policy, even though the Cisco ACI object showed that trust was established. After checking the cloud_proxy.elg file, it showed that our MDS had lost trust with the APIC, but it wasn't obvious when checking the dashboard object.&lt;/P&gt;</description>
      <pubDate>Thu, 01 May 2025 21:32:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Machines-in-EPG-Cisco-ACI-are-rebooted-but-not-updated-on/m-p/247959#M48435</guid>
      <dc:creator>AaronCP</dc:creator>
      <dc:date>2025-05-01T21:32:07Z</dc:date>
    </item>
  </channel>
</rss>

