<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Identity Awareness randomly loosing identitys in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-randomly-loosing-identitys/m-p/256641#M50275</link>
    <description>&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Hello everyone, I use Identity Awareness on all our gateways.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;We get the identities from the Identity Collector, which I installed on each domain controller.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Most locations have only one DC.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;The problem I'm having is at the main site.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I have three domain controllers with three Identity Collectors there.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;It's working quite well so far, but unfortunately, sometimes individual users lose their identity.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;From one second to the next.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I then see in the log that only the IP address is displayed and no longer the username!&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; I've attached a screenshot of the log.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;In this example, the user "Emanuel" suddenly loses his "identity." This is, of course, extremely unfortunate, since our rules are based entirely on Identity Awareness.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; I checked in the CLI whether the gateway still recognizes the user and has the correct IP assignment.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Result: Yes, everything is still there.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;The IP address matches the username.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Nevertheless, as you can see, he falls into a drop rule.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; I suspect it's a timeout issue.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Perhaps an idle timeout?&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I just can't find a way to increase the timeout.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; Or am I on the wrong track and do you have another solution?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; Thank you very much for your help.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;</description>
    <pubDate>Fri, 05 Sep 2025 07:29:31 GMT</pubDate>
    <dc:creator>lesmona</dc:creator>
    <dc:date>2025-09-05T07:29:31Z</dc:date>
    <item>
      <title>Identity Awareness randomly loosing identitys</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-randomly-loosing-identitys/m-p/256641#M50275</link>
      <description>&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Hello everyone, I use Identity Awareness on all our gateways.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;We get the identities from the Identity Collector, which I installed on each domain controller.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Most locations have only one DC.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;The problem I'm having is at the main site.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I have three domain controllers with three Identity Collectors there.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;It's working quite well so far, but unfortunately, sometimes individual users lose their identity.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;From one second to the next.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I then see in the log that only the IP address is displayed and no longer the username!&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; I've attached a screenshot of the log.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;In this example, the user "Emanuel" suddenly loses his "identity." This is, of course, extremely unfortunate, since our rules are based entirely on Identity Awareness.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; I checked in the CLI whether the gateway still recognizes the user and has the correct IP assignment.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Result: Yes, everything is still there.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;The IP address matches the username.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Nevertheless, as you can see, he falls into a drop rule.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; I suspect it's a timeout issue.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Perhaps an idle timeout?&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I just can't find a way to increase the timeout.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; Or am I on the wrong track and do you have another solution?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; Thank you very much for your help.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 05 Sep 2025 07:29:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-randomly-loosing-identitys/m-p/256641#M50275</guid>
      <dc:creator>lesmona</dc:creator>
      <dc:date>2025-09-05T07:29:31Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness randomly loosing identitys</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-randomly-loosing-identitys/m-p/256673#M50281</link>
      <description>&lt;P&gt;Without knowing more about your environment, which includes:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Version/JHF of gateways and management&lt;/LI&gt;
&lt;LI&gt;Version of Identity Collector&lt;/LI&gt;
&lt;LI&gt;The relationship between Identity Collector, Active Directory, and Gateways&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;It's hard to know where to start on this.&lt;BR /&gt;The actual log in/out events, which are shown in the screenshot provided, should be reviewed to see if they provide any clues.&lt;BR /&gt;You will need to see the full log card.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Sep 2025 17:20:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-randomly-loosing-identitys/m-p/256673#M50281</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-09-05T17:20:54Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness randomly loosing identitys</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-randomly-loosing-identitys/m-p/256713#M50283</link>
      <description>&lt;P&gt;This is the IA debug TAC gave me while back, so you can definitely run it and see if it helps. I do agree with Phoneboy that we need full log details, just blour out any sentisive data.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;debugs:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;# cd $FWDIR/log&lt;BR /&gt;# rm pdpd.elg.*&lt;BR /&gt;# echo "=debug_start=" &amp;gt;&amp;gt; $FWDIR/log/pdpd.elg&lt;BR /&gt;(•) To turn pdp debug on:&lt;BR /&gt;# adlog a d on&lt;BR /&gt;# pdp debug on&lt;BR /&gt;# pep debug on&lt;BR /&gt;# pdp debug set all all&lt;BR /&gt;(•) Replicate the issue&lt;BR /&gt;(•) To turn them off:&lt;BR /&gt;# adlog a d off&lt;BR /&gt;# pdp debug unset all all&lt;BR /&gt;# pdp debug off&lt;BR /&gt;# pep debug off&lt;BR /&gt;# pdp d reset&lt;BR /&gt;# pep d unset all all&lt;BR /&gt;Collect debug:&lt;BR /&gt;$FWDIR/log/pdpd.elg&lt;BR /&gt;# tar zcvf pdpd_debugs.tgz pdpd.elg*&lt;BR /&gt;# tar zcvf pepd_debugs.tgz pepd.elg*&lt;/P&gt;</description>
      <pubDate>Sun, 07 Sep 2025 19:21:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-randomly-loosing-identitys/m-p/256713#M50283</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-07T19:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness randomly loosing identitys</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-randomly-loosing-identitys/m-p/256766#M50297</link>
      <description>&lt;P&gt;Hello everyone,&lt;BR /&gt;I've learned something new: the "pdp control sync" command fixes my problem, and it works again immediately. Now, of course, the question is why the database isn't replicating properly in the cluster system with R81.20 Take 113. Are there any settings or something similar?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Sep 2025 14:15:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-randomly-loosing-identitys/m-p/256766#M50297</guid>
      <dc:creator>lesmona</dc:creator>
      <dc:date>2025-09-08T14:15:20Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness randomly loosing identitys</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-randomly-loosing-identitys/m-p/256768#M50298</link>
      <description>&lt;P&gt;Just tried it on both R81.20 and R82. but get below...&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;[Expert@CP-FW-01:0]# pep control sync&lt;BR /&gt;Command: root-&amp;gt;control&lt;BR /&gt;Unknown option: sync&lt;/P&gt;
&lt;P&gt;Available options:&lt;BR /&gt;portal_dual_stack - portal dual stack (IPv4 and IPv6) support&lt;BR /&gt;extended_info_storage - should the PEP store extended identities info for debugging or not&lt;BR /&gt;tasks_manager - the task manager menu&lt;BR /&gt;kbuf_cache - Kbuf cache configuration&lt;BR /&gt;gbuf_cache - Gbuf cache configuration&lt;BR /&gt;identity_cache_mode - Identity Cache mode configuration&lt;/P&gt;
&lt;P&gt;[Expert@CP-FW-01:0]#&lt;/P&gt;</description>
      <pubDate>Mon, 08 Sep 2025 14:06:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-randomly-loosing-identitys/m-p/256768#M50298</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-08T14:06:43Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness randomly loosing identitys</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-randomly-loosing-identitys/m-p/256769#M50299</link>
      <description>&lt;P&gt;sorry :&amp;nbsp;&amp;nbsp;pdp control sync&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Sep 2025 14:11:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-randomly-loosing-identitys/m-p/256769#M50299</guid>
      <dc:creator>lesmona</dc:creator>
      <dc:date>2025-09-08T14:11:05Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness randomly loosing identitys</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-randomly-loosing-identitys/m-p/256770#M50300</link>
      <description>&lt;P&gt;Thats better : - )&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;[Expert@CP-FW-01:0]# pdp control sync&lt;BR /&gt;a sync message will be sent to relevant gateways&lt;BR /&gt;[Expert@CP-FW-01:0]#&lt;/P&gt;</description>
      <pubDate>Mon, 08 Sep 2025 14:12:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-randomly-loosing-identitys/m-p/256770#M50300</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-08T14:12:26Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness randomly loosing identitys</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-randomly-loosing-identitys/m-p/256840#M50340</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I have to manually initiate the sync every now and then.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Is there a way to check why this is happening?&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I can't do this manual sync multiple times a day when it should happen automatically.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 09 Sep 2025 07:29:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-randomly-loosing-identitys/m-p/256840#M50340</guid>
      <dc:creator>lesmona</dc:creator>
      <dc:date>2025-09-09T07:29:12Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness randomly loosing identitys</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-randomly-loosing-identitys/m-p/256853#M50345</link>
      <description>&lt;P&gt;How often though?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 09 Sep 2025 10:22:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-randomly-loosing-identitys/m-p/256853#M50345</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-09T10:22:45Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness randomly loosing identitys</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-randomly-loosing-identitys/m-p/256857#M50348</link>
      <description>&lt;P&gt;today like 10 times.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Sep 2025 11:39:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-randomly-loosing-identitys/m-p/256857#M50348</guid>
      <dc:creator>lesmona</dc:creator>
      <dc:date>2025-09-09T11:39:57Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness randomly loosing identitys</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-randomly-loosing-identitys/m-p/256858#M50349</link>
      <description>&lt;P&gt;That is not normal, for sure. I would open TAC case to investigate.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Sep 2025 11:41:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-randomly-loosing-identitys/m-p/256858#M50349</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-09T11:41:44Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness randomly loosing identitys</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-randomly-loosing-identitys/m-p/256898#M50355</link>
      <description>&lt;P&gt;Running the command periodically via cron might be a good idea in the short term while you investigate the issue with TAC,&lt;/P&gt;</description>
      <pubDate>Tue, 09 Sep 2025 15:13:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-randomly-loosing-identitys/m-p/256898#M50355</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-09-09T15:13:02Z</dc:date>
    </item>
  </channel>
</rss>

