<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem of connection of users to the VPN in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Problem-of-connection-of-users-to-the-VPN/m-p/190330#M31884</link>
    <description>&lt;P&gt;Never had an issue like that before. Question...I assume you are using access roles? If you do pdp monitor user command, do you even see anything?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Wed, 23 Aug 2023 15:42:12 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-08-23T15:42:12Z</dc:date>
    <item>
      <title>Problem of connection of users to the VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-of-connection-of-users-to-the-VPN/m-p/190329#M31883</link>
      <description>&lt;P&gt;Hello, everyone.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We currently have a connection problem for users trying to connect via VPN to the GW (Using Endpoint Security).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Initially, everything was working fine with the AD Query method (We have Mobile Access and IA blades enabled).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now, since we migrated the way AD users work, from AD Query to IDC, we are having problems with a lot of users not being able to connect to the VPN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have checked that in the IDC, if there is an association between an IP + User.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But it seems that this information stays in the IDC, and does not send it to the Firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since when we consult for certain user that is seen in the IDC, it does not appear in the "pdp" commands that we apply in the GW.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have made connection tests, with local GW accounts, and everything works fine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any opinion and/or similar experience you can share?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 15:32:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-of-connection-of-users-to-the-VPN/m-p/190329#M31883</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-08-23T15:32:45Z</dc:date>
    </item>
    <item>
      <title>Re: Problem of connection of users to the VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-of-connection-of-users-to-the-VPN/m-p/190330#M31884</link>
      <description>&lt;P&gt;Never had an issue like that before. Question...I assume you are using access roles? If you do pdp monitor user command, do you even see anything?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 15:42:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-of-connection-of-users-to-the-VPN/m-p/190330#M31884</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-23T15:42:12Z</dc:date>
    </item>
    <item>
      <title>Re: Problem of connection of users to the VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-of-connection-of-users-to-the-VPN/m-p/190331#M31885</link>
      <description>&lt;P&gt;Yes, we are working the rules with Access Role.&lt;/P&gt;
&lt;P&gt;In the SMS logs, the message "Unknown User" appears.&lt;/P&gt;
&lt;P&gt;The strange thing is that the users are seen in the IDC (IP+User Association).&lt;/P&gt;
&lt;P&gt;But in the GW Cluster, the user is not seen when searching with the command "pdp ...".&lt;/P&gt;
&lt;P&gt;So, because of this, remote users cannot connect.&lt;/P&gt;
&lt;P&gt;This happened after migrating from AD Query to IDC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 15:47:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-of-connection-of-users-to-the-VPN/m-p/190331#M31885</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-08-23T15:47:31Z</dc:date>
    </item>
    <item>
      <title>Re: Problem of connection of users to the VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-of-connection-of-users-to-the-VPN/m-p/190333#M31886</link>
      <description>&lt;P&gt;This is the evidence, from what I see with the "pdp" command in the GW.&lt;/P&gt;
&lt;P&gt;The user does not appear in the GW.&lt;/P&gt;
&lt;P&gt;But this same user does appear in the IDC.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PDP.png" style="width: 843px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22189iB7DA011F3343C99B/image-size/large?v=v2&amp;amp;px=999" role="button" title="PDP.png" alt="PDP.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 15:50:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-of-connection-of-users-to-the-VPN/m-p/190333#M31886</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-08-23T15:50:00Z</dc:date>
    </item>
    <item>
      <title>Re: Problem of connection of users to the VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-of-connection-of-users-to-the-VPN/m-p/190334#M31887</link>
      <description>&lt;P&gt;Make sure LDAP account unit is still there, as thats needed to pull the groups from AD properly, as&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;mentioned in another post.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Identity-Collector/m-p/190000/emcs_t/S2h8ZW1haWx8dG9waWNfc3Vic2NyaXB0aW9ufExMTDBKVTRTTUc3V1NIfDE5MDAwMHxTVUJTQ1JJUFRJT05TfGhL#M35047" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Identity-Collector/m-p/190000/emcs_t/S2h8ZW1haWx8dG9waWNfc3Vic2NyaXB0aW9ufExMTDBKVTRTTUc3V1NIfDE5MDAwMHxTVUJTQ1JJUFRJT05TfGhL#M35047&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 15:50:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-of-connection-of-users-to-the-VPN/m-p/190334#M31887</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-23T15:50:06Z</dc:date>
    </item>
    <item>
      <title>Re: Problem of connection of users to the VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-of-connection-of-users-to-the-VPN/m-p/190336#M31888</link>
      <description>&lt;P&gt;The account that was used to hook the IDC to the AD still exists.&lt;/P&gt;
&lt;P&gt;Is there a way to reboot, do a sniffer or capture, that will help us to know why the AD users do not arrive to the GW, but they do arrive to the IDC?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 16:14:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-of-connection-of-users-to-the-VPN/m-p/190336#M31888</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-08-23T16:14:28Z</dc:date>
    </item>
    <item>
      <title>Re: Problem of connection of users to the VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-of-connection-of-users-to-the-VPN/m-p/190339#M31890</link>
      <description>&lt;P&gt;Reboot wont do anything for this sort of issue. Can you still see same LDAP account unit? Are there any logs for the tested user in smart console? You can do IA debugs TAC gave me while back, hope they give some clues.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 16:31:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-of-connection-of-users-to-the-VPN/m-p/190339#M31890</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-23T16:31:39Z</dc:date>
    </item>
    <item>
      <title>Re: Problem of connection of users to the VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-of-connection-of-users-to-the-VPN/m-p/190403#M31908</link>
      <description>&lt;P&gt;To test with these TAC debug commands, you would have to test punctually, with a user that is affected with his VPN connection, correct?&lt;/P&gt;
&lt;P&gt;Is there a way to "delete" his session, in the IDC, to be able to apply the process from 0, with a punctual user?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 23:05:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-of-connection-of-users-to-the-VPN/m-p/190403#M31908</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-08-23T23:05:47Z</dc:date>
    </item>
    <item>
      <title>Re: Problem of connection of users to the VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-of-connection-of-users-to-the-VPN/m-p/190405#M31909</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Thats right. Im not aware if way to debug IC, as its not a process.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 23:19:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-of-connection-of-users-to-the-VPN/m-p/190405#M31909</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-23T23:19:04Z</dc:date>
    </item>
    <item>
      <title>Re: Problem of connection of users to the VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-of-connection-of-users-to-the-VPN/m-p/190512#M31926</link>
      <description>&lt;P&gt;It's not in Identity Collector that you need to delete the user, but in PDP on the relevant gateway.&lt;BR /&gt;The identities that relate to a given IP address can be revoked using the CLI command: pdp control revoke x.y.z.w&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_IdentityAwareness_AdminGuide/Topics-IDAG/CLI/pdp-control.htm?tocpath=Command%20Line%20Reference%7Cpdp%7C_____6" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_IdentityAwareness_AdminGuide/Topics-IDAG/CLI/pdp-control.htm?tocpath=Command%20Line%20Reference%7Cpdp%7C_____6&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2023 21:55:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-of-connection-of-users-to-the-VPN/m-p/190512#M31926</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-08-24T21:55:14Z</dc:date>
    </item>
    <item>
      <title>Re: Problem of connection of users to the VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-of-connection-of-users-to-the-VPN/m-p/190528#M31929</link>
      <description>&lt;P&gt;Did you make any progress on this bro? Also, maybe try pdp update all command to see if any difference.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2023 22:59:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-of-connection-of-users-to-the-VPN/m-p/190528#M31929</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-24T22:59:14Z</dc:date>
    </item>
    <item>
      <title>Re: Problem of connection of users to the VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-of-connection-of-users-to-the-VPN/m-p/190532#M31930</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;The problem is that users are not "seen" in the GW.&lt;/P&gt;
&lt;P&gt;For example:&lt;/P&gt;
&lt;P&gt;User: Pepito&lt;BR /&gt;IP: 10.10.10.10&lt;/P&gt;
&lt;P&gt;This association is seen in the IDC, but in the GW, it is not "seen", that's why I think, that applying the command you suggest, would not help me in this case.&lt;/P&gt;
&lt;P&gt;It seems that the relationship between the IDC and the GW is not working well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 01:02:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-of-connection-of-users-to-the-VPN/m-p/190532#M31930</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-08-25T01:02:05Z</dc:date>
    </item>
    <item>
      <title>Re: Problem of connection of users to the VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-of-connection-of-users-to-the-VPN/m-p/190534#M31931</link>
      <description>&lt;P&gt;If you do pdp monitor ip and then user IP, you dont see anything?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 01:48:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-of-connection-of-users-to-the-VPN/m-p/190534#M31931</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-25T01:48:31Z</dc:date>
    </item>
    <item>
      <title>Re: Problem of connection of users to the VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-of-connection-of-users-to-the-VPN/m-p/190536#M31932</link>
      <description>&lt;P&gt;Buddy,&lt;/P&gt;
&lt;P&gt;In the GW you do not see the users who have already registered in the IDC.&lt;/P&gt;
&lt;P&gt;At the top of this post, I pasted some images of a user.&lt;BR /&gt;This user in the IDC, if his IP+User relationship appears, but when you query for this user in the GW, it simply does not see it.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 03:15:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-of-connection-of-users-to-the-VPN/m-p/190536#M31932</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-08-25T03:15:06Z</dc:date>
    </item>
    <item>
      <title>Re: Problem of connection of users to the VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-of-connection-of-users-to-the-VPN/m-p/190561#M31936</link>
      <description>&lt;P&gt;Maybe try restart IC and see what happens.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 10:16:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-of-connection-of-users-to-the-VPN/m-p/190561#M31936</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-25T10:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: Problem of connection of users to the VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-of-connection-of-users-to-the-VPN/m-p/190578#M31943</link>
      <description>&lt;P&gt;We are still reviewing this atypical case.&lt;/P&gt;
&lt;P&gt;How do you reset the IDC?&lt;/P&gt;
&lt;P&gt;I'm going to try the last command you recommended, let's see how it goes.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 12:18:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-of-connection-of-users-to-the-VPN/m-p/190578#M31943</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-08-25T12:18:29Z</dc:date>
    </item>
    <item>
      <title>Re: Problem of connection of users to the VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-of-connection-of-users-to-the-VPN/m-p/190582#M31944</link>
      <description>&lt;P&gt;You dont : - ). You either restart it from task manager or simply reboot computer software is installed on.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 12:25:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-of-connection-of-users-to-the-VPN/m-p/190582#M31944</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-25T12:25:55Z</dc:date>
    </item>
  </channel>
</rss>

