<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PDP/PEP Identity Sharing Not In Sync? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-PEP-Identity-Sharing-Not-In-Sync/m-p/51541#M86390</link>
    <description>That's definitely TAC case territory.&lt;BR /&gt;Version/JHF level?</description>
    <pubDate>Tue, 23 Apr 2019 02:18:10 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2019-04-23T02:18:10Z</dc:date>
    <item>
      <title>PDP/PEP Identity Sharing Not In Sync?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-PEP-Identity-Sharing-Not-In-Sync/m-p/51527#M86389</link>
      <description>&lt;P&gt;I will likely open a TAC case on this, but we noticed today that one GW using identity sharing today seems to not be fully in sync with the PDP. For example, if I run&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;pep show user all |grep &amp;lt;username&amp;gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;on the PDP, I am able to see a record existing for that user. However, when I go to the GW acting as the PEP, the same command returns no entries. It seems completely random as to the users impacted, but it is definitely messing with some App Control rules from working!&lt;BR /&gt;&lt;BR /&gt;I've tried using&amp;nbsp;&lt;STRONG&gt;&lt;I&gt;pdp update all&lt;/I&gt;&lt;/STRONG&gt; and&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;pdp control sync&lt;/STRONG&gt;&lt;/EM&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;to try to force updates. I have also tried pushing policy again to both GW. Has anyone else ever seen this? Are they any other commands or troubleshooting recommended before possibly engaging TAC?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;From the PDP Gateway:&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;pep show pdp all&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;Command: root-&amp;gt;show-&amp;gt;pdp-&amp;gt;all&lt;BR /&gt;-----------------------------------------------------------------------&lt;BR /&gt;| Direction | IP | ID | Status | Users | Connect time |&lt;BR /&gt;-----------------------------------------------------------------------&lt;BR /&gt;| Incoming | 127.0.0.1 | 0 | Connected | &lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;460&lt;/STRONG&gt;&lt;/FONT&gt; | 21Feb2019 6:16:33 |&lt;BR /&gt;-----------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;From the PEP Gateway with Identity Sharing enabled to sync identities with the GW above:&lt;BR /&gt;pep show pdp all&lt;BR /&gt;Command: root-&amp;gt;show-&amp;gt;pdp-&amp;gt;all&lt;BR /&gt;-------------------------------------------------------------------------&lt;BR /&gt;| Direction | IP | ID | Status | Users | Connect time |&lt;BR /&gt;-------------------------------------------------------------------------&lt;BR /&gt;| Incoming | IP OF PDP GW | 0 | Connected | &lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;391&lt;/STRONG&gt;&lt;/FONT&gt; | 8Apr2019 5:25:44 |&lt;BR /&gt;-------------------------------------------------------------------------&lt;BR /&gt;| Incoming | 127.0.0.1 | 0 | Connected | 0 | 8Apr2019 5:16:48 |&lt;BR /&gt;-------------------------------------------------------------------------&lt;BR /&gt;| Outgoing | IP OF PDP GW | 0 | Connected | N/A | 8Apr2019 5:17:08 |&lt;BR /&gt;-------------------------------------------------------------------------&lt;/P&gt;</description>
      <pubDate>Mon, 22 Apr 2019 19:38:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-PEP-Identity-Sharing-Not-In-Sync/m-p/51527#M86389</guid>
      <dc:creator>Daniel_Taney</dc:creator>
      <dc:date>2019-04-22T19:38:20Z</dc:date>
    </item>
    <item>
      <title>Re: PDP/PEP Identity Sharing Not In Sync?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-PEP-Identity-Sharing-Not-In-Sync/m-p/51541#M86390</link>
      <description>That's definitely TAC case territory.&lt;BR /&gt;Version/JHF level?</description>
      <pubDate>Tue, 23 Apr 2019 02:18:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-PEP-Identity-Sharing-Not-In-Sync/m-p/51541#M86390</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-04-23T02:18:10Z</dc:date>
    </item>
    <item>
      <title>Re: PDP/PEP Identity Sharing Not In Sync?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-PEP-Identity-Sharing-Not-In-Sync/m-p/51588#M86391</link>
      <description>&lt;P&gt;Both PDP and PEP are R80.20, Take 47&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2019 12:35:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-PEP-Identity-Sharing-Not-In-Sync/m-p/51588#M86391</guid>
      <dc:creator>Daniel_Taney</dc:creator>
      <dc:date>2019-04-23T12:35:32Z</dc:date>
    </item>
    <item>
      <title>Re: PDP/PEP Identity Sharing Not In Sync?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-PEP-Identity-Sharing-Not-In-Sync/m-p/60639#M86392</link>
      <description>Did you find a solution for this?</description>
      <pubDate>Mon, 19 Aug 2019 14:23:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-PEP-Identity-Sharing-Not-In-Sync/m-p/60639#M86392</guid>
      <dc:creator>Nik_Bloemers</dc:creator>
      <dc:date>2019-08-19T14:23:41Z</dc:date>
    </item>
    <item>
      <title>Re: PDP/PEP Identity Sharing Not In Sync?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-PEP-Identity-Sharing-Not-In-Sync/m-p/62910#M86393</link>
      <description>&lt;P&gt;We had a similar issue. It was due to two separate clusters both doing ADquery and both clusters also set to share identities with each other. Caused random users to get dropped off every now and then.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2019 06:23:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-PEP-Identity-Sharing-Not-In-Sync/m-p/62910#M86393</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2019-09-17T06:23:26Z</dc:date>
    </item>
    <item>
      <title>Re: PDP/PEP Identity Sharing Not In Sync?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-PEP-Identity-Sharing-Not-In-Sync/m-p/83056#M86394</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/14416"&gt;@Ryan_Ryan&lt;/a&gt;&amp;nbsp; How did you solve the issue with doing AD query on multiple clusters and sharing with each other?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or rather is it not the correct configuration from design point of view?&lt;/P&gt;&lt;P&gt;We are facing a similar issue....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your feedback!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Nenad&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2020 10:45:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-PEP-Identity-Sharing-Not-In-Sync/m-p/83056#M86394</guid>
      <dc:creator>Nenad_D</dc:creator>
      <dc:date>2020-04-24T10:45:34Z</dc:date>
    </item>
    <item>
      <title>Re: PDP/PEP Identity Sharing Not In Sync?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-PEP-Identity-Sharing-Not-In-Sync/m-p/83400#M86395</link>
      <description>&lt;P&gt;You must choose either one of these methods (and not mix them)&lt;/P&gt;&lt;P&gt;1) One gateway does AD Query and set to share to all other gateways (no ADquery on the other gateways)&lt;/P&gt;&lt;P&gt;2) all gateways do ADquery and all sharing is disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We went with option 1. Then we still had an issue where one or two users only (and always same users) would be present in PDP but not pep at random times, So issue was not completely fixed, we then installed take 141 (r80.20) which has some fixes for PEP out of sync and so far. issue has not returned so far..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2020 22:01:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-PEP-Identity-Sharing-Not-In-Sync/m-p/83400#M86395</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2020-04-27T22:01:30Z</dc:date>
    </item>
    <item>
      <title>Re: PDP/PEP Identity Sharing Not In Sync?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-PEP-Identity-Sharing-Not-In-Sync/m-p/83448#M86396</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/14416"&gt;@Ryan_Ryan&lt;/a&gt;&amp;nbsp;Thanks very much for your feedback! I will give it a try...&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2020 07:51:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-PEP-Identity-Sharing-Not-In-Sync/m-p/83448#M86396</guid>
      <dc:creator>Nenad_D</dc:creator>
      <dc:date>2020-04-28T07:51:36Z</dc:date>
    </item>
    <item>
      <title>Re: PDP/PEP Identity Sharing Not In Sync?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-PEP-Identity-Sharing-Not-In-Sync/m-p/84137#M86397</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/45381"&gt;@Nenad_D&lt;/a&gt;&amp;nbsp; Also we have a setup with separate PDP gateways (2 x PDP -With Cluster Setup ) for ADQ and another set (2 xPDP With Cluster Setup) for the IDC .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have mixed environment of older Win2003 servers and we wanted to separate the WMI process with the IDC . We do identity sharing with the VS we have , using the cluster ips of the PDPs (one cluster ip for ADQ &amp;amp; one cluster ip for IDC )&amp;nbsp; .&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems to work good , except some problems with users that do not shut down the PCs , so we don't have log in/out security logs .Also we have noticed some times that the PDPs know a user , but the PEP not . Usually with pdp control sync it works .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards&amp;nbsp;&lt;/P&gt;&lt;P&gt;Prodromos&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2020 20:14:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-PEP-Identity-Sharing-Not-In-Sync/m-p/84137#M86397</guid>
      <dc:creator>LaRockas</dc:creator>
      <dc:date>2020-05-04T20:14:55Z</dc:date>
    </item>
  </channel>
</rss>

