<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PEP not enforcing all roles in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/PEP-not-enforcing-all-roles/m-p/178396#M29724</link>
    <description>&lt;P&gt;Just in case what i am usually setting:&lt;/P&gt;&lt;DIV&gt;&lt;TABLE border="1" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;Ia_max_authenticated_users&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;200000&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;Ia_max_enforced_identities&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;200000&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;</description>
    <pubDate>Tue, 18 Apr 2023 14:51:15 GMT</pubDate>
    <dc:creator>Vincent_Bacher</dc:creator>
    <dc:date>2023-04-18T14:51:15Z</dc:date>
    <item>
      <title>PEP not enforcing all roles</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PEP-not-enforcing-all-roles/m-p/178344#M29710</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are currently experiencing issues with Identity Awareness. PEP gateways arent enforcing access roles for all users. This seems to be affecting various amounts of users, and a workaround has been to restart the pep daemon, which is not a proper fix.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The setup is pretty standard, with 3 pdp gateways feeding identities to some pep gateways. This has been working quite well, but last week, we noticed an increase in users losing access to resourcec, where the rules are based on access roles.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Identity source is identity collector, and service accounts are excluded. Identity collectors appear to be working fine, and i see plenty of events being registered, same with users and machines.&lt;/P&gt;&lt;P&gt;Not sure if there are problems with cache, time to live or other of the settings? What would be the potential risk of changing any of these values, and if so, are there any recommendation on what to set?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are running r81.10, t66&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 07:41:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PEP-not-enforcing-all-roles/m-p/178344#M29710</guid>
      <dc:creator>KM1895</dc:creator>
      <dc:date>2023-04-18T07:41:35Z</dc:date>
    </item>
    <item>
      <title>Re: PEP not enforcing all roles</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PEP-not-enforcing-all-roles/m-p/178354#M29715</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;did you check for problematic users if the session is visible at the pep using pep s u q usr &amp;lt;loginname&amp;gt; ?&lt;BR /&gt;If yes, are the roles listed? If not, do you see any role calculation issues maybe with AD controllers?&lt;BR /&gt;&lt;BR /&gt;br&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 08:51:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PEP-not-enforcing-all-roles/m-p/178354#M29715</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2023-04-18T08:51:58Z</dc:date>
    </item>
    <item>
      <title>Re: PEP not enforcing all roles</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PEP-not-enforcing-all-roles/m-p/178359#M29716</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;I havent checked, but i think someone else checked this earlier. We are suspecting full pdp and pep kernel tables, as the gateways are still on the default 30.000. The main pdp currently has 42k identified users and machines. so we will probably try to expand these, and clear the tables.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 09:37:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PEP-not-enforcing-all-roles/m-p/178359#M29716</guid>
      <dc:creator>KM1895</dc:creator>
      <dc:date>2023-04-18T09:37:06Z</dc:date>
    </item>
    <item>
      <title>Re: PEP not enforcing all roles</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PEP-not-enforcing-all-roles/m-p/178379#M29721</link>
      <description>&lt;P&gt;Yes, i would then as well recommend extending the tables, we have this issue as well whenever we forget to set the table sizes accordingly when deploying new devices using ia.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 13:00:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PEP-not-enforcing-all-roles/m-p/178379#M29721</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2023-04-18T13:00:55Z</dc:date>
    </item>
    <item>
      <title>Re: PEP not enforcing all roles</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PEP-not-enforcing-all-roles/m-p/178395#M29723</link>
      <description>&lt;P&gt;I attached debug TAC gave me while ago for pdp/pep debugs, so might be worth doing those (well, just pep in your case)&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 14:50:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PEP-not-enforcing-all-roles/m-p/178395#M29723</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-04-18T14:50:25Z</dc:date>
    </item>
    <item>
      <title>Re: PEP not enforcing all roles</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PEP-not-enforcing-all-roles/m-p/178396#M29724</link>
      <description>&lt;P&gt;Just in case what i am usually setting:&lt;/P&gt;&lt;DIV&gt;&lt;TABLE border="1" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;Ia_max_authenticated_users&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;200000&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;Ia_max_enforced_identities&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;200000&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 18 Apr 2023 14:51:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PEP-not-enforcing-all-roles/m-p/178396#M29724</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2023-04-18T14:51:15Z</dc:date>
    </item>
    <item>
      <title>Re: PEP not enforcing all roles</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PEP-not-enforcing-all-roles/m-p/178397#M29725</link>
      <description>&lt;P&gt;In addition because of possible very high amount of logs, i increase log size and number of rotated elg before starting debug and resetting same afterwards&lt;BR /&gt;&lt;BR /&gt;before:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;fw debug fwd off PDP_LOG_SIZE=50000000
fw debug fwd off PDP_NUM_LOGS=20
fw debug fwd off PEP_LOG_SIZE=50000000
fw debug fwd off PEP_NUM_LOGS=20

fw kill pdpd
fw kill pepd&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;after&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;fw debug fwd off PDP_LOG_SIZE=10000000
fw debug fwd off PDP_NUM_LOGS=10
fw debug fwd off PEP_LOG_SIZE=10000000
fw debug fwd off PEP_NUM_LOGS=10

fw kill pdpd
fw kill pepd&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 18 Apr 2023 14:56:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PEP-not-enforcing-all-roles/m-p/178397#M29725</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2023-04-18T14:56:13Z</dc:date>
    </item>
  </channel>
</rss>

