<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IA sharing at scale in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/IA-sharing-at-scale/m-p/195056#M32657</link>
    <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;we use dedicated PDP Brokers. The firewall itselfs only do the pep enforcement. We completly seperated these two services from each other. These PDP Brokers are full meshed to share all identies with each other. The peps only consume the identies from their local PDP Broker.&lt;BR /&gt;&lt;BR /&gt;We don't need to kill pep / pdp every night.&lt;BR /&gt;&lt;BR /&gt;We setup a centralised IA PDP Broker for every region.&lt;BR /&gt;&lt;BR /&gt;We switched from our full meshed design to PDP Brokers in 2021. I draw our design and uploaded it here:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ProxyOps_1-1697200005813.jpeg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22801iE1D7A28EAE0A2032/image-size/large?v=v2&amp;amp;px=999" role="button" title="ProxyOps_1-1697200005813.jpeg" alt="ProxyOps_1-1697200005813.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;If you want more informations, feel free to contact me via private message.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 13 Oct 2023 16:19:51 GMT</pubDate>
    <dc:creator>ProxyOps</dc:creator>
    <dc:date>2023-10-13T16:19:51Z</dc:date>
    <item>
      <title>IA sharing at scale</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IA-sharing-at-scale/m-p/194630#M32579</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;We manage 50+ gw with full meshed IA sharing.&lt;/P&gt;&lt;P&gt;We face lot of isues with IA.&lt;BR /&gt;Some random IA not propagated accross gw, some random IA agents not able to connect to their local gw...&lt;BR /&gt;Something that improve the behavior a little bit is a cronjob to kill pep and pdp every night...&lt;/P&gt;&lt;P&gt;We think about centralising IA on a dedicated gw, so IA agents connect to this specific gw and it redistribute IA to all gw.&lt;/P&gt;&lt;P&gt;It's a big change that cannot be fully tested outside production and we are a little bit afraid things get worse than now.&lt;/P&gt;&lt;P&gt;How do you folks manage IA at scale?&lt;BR /&gt;Do you have to kill pep and pdp every night too?&lt;BR /&gt;Do you centralise IA to a single sharing gw?&lt;/P&gt;&lt;P&gt;Thanks for your advises.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 08:58:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IA-sharing-at-scale/m-p/194630#M32579</guid>
      <dc:creator>fdhfdshs5454</dc:creator>
      <dc:date>2023-10-10T08:58:28Z</dc:date>
    </item>
    <item>
      <title>Re: IA sharing at scale</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IA-sharing-at-scale/m-p/194642#M32580</link>
      <description>&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk88520" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk88520: Best Practices - &lt;STRONG&gt;Identity&lt;/STRONG&gt; &lt;STRONG&gt;Awareness&lt;/STRONG&gt; Large Scale Deployment&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 10:14:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IA-sharing-at-scale/m-p/194642#M32580</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-10-10T10:14:14Z</dc:date>
    </item>
    <item>
      <title>Re: IA sharing at scale</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IA-sharing-at-scale/m-p/194650#M32581</link>
      <description>&lt;P&gt;Yes, I read that.&lt;/P&gt;&lt;P&gt;I want to know administator feedback about IA sharing in general, this solution or others they may have deployed to fix IA.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 10:32:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IA-sharing-at-scale/m-p/194650#M32581</guid>
      <dc:creator>fdhfdshs5454</dc:creator>
      <dc:date>2023-10-10T10:32:27Z</dc:date>
    </item>
    <item>
      <title>Re: IA sharing at scale</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IA-sharing-at-scale/m-p/194654#M32582</link>
      <description>&lt;P&gt;R81.20 has some relevant IA enhancements...&lt;/P&gt;
&lt;P&gt;Are you using any of the following today and what version are the current Gateways?&lt;/P&gt;
&lt;P&gt;- Identity Collector&lt;/P&gt;
&lt;P&gt;- Identity Broker&lt;/P&gt;
&lt;P&gt;- Dedicated PDPs&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 11:29:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IA-sharing-at-scale/m-p/194654#M32582</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-10-10T11:29:03Z</dc:date>
    </item>
    <item>
      <title>Re: IA sharing at scale</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IA-sharing-at-scale/m-p/194788#M32608</link>
      <description>&lt;P&gt;We are currently running R81.10 HFA110 on every gw.&lt;/P&gt;&lt;P&gt;We'll upgrade to R81.20 as soon as we get a maintenance windows.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Identity Collector: No. We don't use ADQuery. Only IA agents. Plus, each remote gateway fetch from its local DC&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Identity Broker: No. We didn't invest in it as the configuration involve files modifications with complex syntax on every firewalls. Now, if you tell us it enhance the UX, we'll consider it. But how is it different from "classical" PDP? Why is it not the default PDP mecanism?&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Dedicated PDPs: No. That's what this post is all about... Is it a good move? Is the user community doing it? what is their feeddback?...&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Wed, 11 Oct 2023 11:16:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IA-sharing-at-scale/m-p/194788#M32608</guid>
      <dc:creator>fdhfdshs5454</dc:creator>
      <dc:date>2023-10-11T11:16:41Z</dc:date>
    </item>
    <item>
      <title>Re: IA sharing at scale</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IA-sharing-at-scale/m-p/194799#M32611</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Please check not resolved issues in IA for R81.20:&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/R81.20/Upcoming-Resolved-Issues.htm?tocpath=_____6" target="_blank"&gt;https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/R81.20/Upcoming-Resolved-Issues.htm?tocpath=_____6&lt;/A&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Daniel.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 12:46:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IA-sharing-at-scale/m-p/194799#M32611</guid>
      <dc:creator>Daniel_Szydelko</dc:creator>
      <dc:date>2023-10-11T12:46:45Z</dc:date>
    </item>
    <item>
      <title>Re: IA sharing at scale</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IA-sharing-at-scale/m-p/195056#M32657</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;we use dedicated PDP Brokers. The firewall itselfs only do the pep enforcement. We completly seperated these two services from each other. These PDP Brokers are full meshed to share all identies with each other. The peps only consume the identies from their local PDP Broker.&lt;BR /&gt;&lt;BR /&gt;We don't need to kill pep / pdp every night.&lt;BR /&gt;&lt;BR /&gt;We setup a centralised IA PDP Broker for every region.&lt;BR /&gt;&lt;BR /&gt;We switched from our full meshed design to PDP Brokers in 2021. I draw our design and uploaded it here:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ProxyOps_1-1697200005813.jpeg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22801iE1D7A28EAE0A2032/image-size/large?v=v2&amp;amp;px=999" role="button" title="ProxyOps_1-1697200005813.jpeg" alt="ProxyOps_1-1697200005813.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;If you want more informations, feel free to contact me via private message.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2023 16:19:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IA-sharing-at-scale/m-p/195056#M32657</guid>
      <dc:creator>ProxyOps</dc:creator>
      <dc:date>2023-10-13T16:19:51Z</dc:date>
    </item>
    <item>
      <title>Re: IA sharing at scale</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IA-sharing-at-scale/m-p/195273#M32738</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Thanks for sharing.&lt;/P&gt;&lt;P&gt;Your setup make sense to us. We will think about making something similar.&lt;/P&gt;&lt;P&gt;Thanks mate!&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 13:20:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IA-sharing-at-scale/m-p/195273#M32738</guid>
      <dc:creator>fdhfdshs5454</dc:creator>
      <dc:date>2023-10-16T13:20:42Z</dc:date>
    </item>
    <item>
      <title>Re: IA sharing at scale</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IA-sharing-at-scale/m-p/195772#M32819</link>
      <description>&lt;P&gt;We are slowly migrating to this setup and it looks like our issues disappear.&lt;/P&gt;&lt;P&gt;Checkpoint should really highlight the usage of very centric PDP to avoid IA sharing issues as soon as 2 firewalls are involved.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 16:08:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IA-sharing-at-scale/m-p/195772#M32819</guid>
      <dc:creator>fdhfdshs5454</dc:creator>
      <dc:date>2023-10-20T16:08:30Z</dc:date>
    </item>
    <item>
      <title>Re: IA sharing at scale</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IA-sharing-at-scale/m-p/196005#M32850</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/34257"&gt;@ProxyOps&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Very interesting design!&lt;/P&gt;&lt;P&gt;Just wondering if your PDP Broker are working with Cluster_XL or not ? Does Cluster_XL synchronize the IA tables ?&lt;/P&gt;&lt;P&gt;Today we have a central design with IA Sharing accross multiples site which is just working fine. Problem is to find window maintenance to upgrade this central IA gateway.&lt;/P&gt;&lt;P&gt;This central Gateway is doing PDP for all users and then share identity with PEP to all remote GW.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 09:42:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IA-sharing-at-scale/m-p/196005#M32850</guid>
      <dc:creator>CP-NDA</dc:creator>
      <dc:date>2023-10-24T09:42:24Z</dc:date>
    </item>
    <item>
      <title>Re: IA sharing at scale</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IA-sharing-at-scale/m-p/196011#M32852</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/13449"&gt;@CP-NDA&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;we are running our PDP Broker as Clusters (Cluster_XL) active-standby on VMs.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Our PDP Brokers are running R81 currently are cluster_xl is not snycing the relevant tables for a interruption free failover.&lt;BR /&gt;When we do a failover the PDP Broker has to sync from scratch again with all over PDP Brokers.&lt;BR /&gt;&lt;BR /&gt;I checked the R81.20 release noted and maybe something was improved here?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;"Improved resiliency, scalability, and stability for PDPs and Identity Broker. Additional threads handle authentication and authorization flows."&lt;BR /&gt;&lt;BR /&gt;I know cluster_xl is syncing some IA tables for PEP but I am not able to find a sk for that.&lt;BR /&gt;&lt;BR /&gt;I have to admit, that we update the PDP Broker Gateways only if required as we need them to be as stable as possible.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 10:58:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IA-sharing-at-scale/m-p/196011#M32852</guid>
      <dc:creator>ProxyOps</dc:creator>
      <dc:date>2023-10-24T10:58:54Z</dc:date>
    </item>
  </channel>
</rss>

