<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Awarness question in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/251895#M42136</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;R81.20 JHF 53&lt;BR /&gt;identity collector.&lt;BR /&gt;&lt;SPAN data-teams="true"&gt;all criteria should match the AR, the AR is configured to use AD groups&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 24 Jun 2025 15:12:33 GMT</pubDate>
    <dc:creator>RemoteUser</dc:creator>
    <dc:date>2025-06-24T15:12:33Z</dc:date>
    <item>
      <title>Identity Awarness question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/251883#M42133</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Users are assigned to the access roles, but the IA system is unable to recognize their accounts within the GRP AD groups that have permissions to access the resources.&lt;BR /&gt;&lt;/SPAN&gt;how can i resolve this. if i do pdp monitor user Jhon123 the output it's empty&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 14:05:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/251883#M42133</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2025-06-24T14:05:29Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awarness question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/251892#M42135</link>
      <description>&lt;P&gt;Please share additional details about the environment including version/jumbo, adquery or identity collector etc&lt;/P&gt;
&lt;P&gt;Have you validated the settings of the account unit, how many are configured ?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 15:03:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/251892#M42135</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-06-24T15:03:11Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awarness question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/251895#M42136</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;R81.20 JHF 53&lt;BR /&gt;identity collector.&lt;BR /&gt;&lt;SPAN data-teams="true"&gt;all criteria should match the AR, the AR is configured to use AD groups&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 15:12:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/251895#M42136</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2025-06-24T15:12:33Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awarness question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/251901#M42139</link>
      <description>&lt;P&gt;We need a lot more information like:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Version/JHF of gateways/management&lt;/LI&gt;
&lt;LI&gt;How you have Identity Awareness set up (what acquisition method(s) are in use)&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;A diagram of the relevant gateways, identity sources, and how they connect to each other and the Internet&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Generally, though, groups come from two places:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The SAML Assertion (when used with Entra ID or other SAML provider)&lt;/LI&gt;
&lt;LI&gt;LDAP queries from the gateway (used with all other identity sources)&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;For troubleshooting, see&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk183118" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk183118&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 15:32:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/251901#M42139</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-06-24T15:32:17Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awarness question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/251903#M42140</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp; as i said:&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;user is not known by the PDP Broker,&amp;nbsp;Identity Collector, we performend a restart of the Identity collector service on the server but nothing change .&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 15:36:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/251903#M42140</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2025-06-24T15:36:26Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awarness question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/251904#M42141</link>
      <description>&lt;P&gt;the sk doesn't exist&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 15:36:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/251904#M42141</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2025-06-24T15:36:47Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awarness question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/251907#M42142</link>
      <description>&lt;P&gt;Sorry, didn't notice that SK was internal.&lt;BR /&gt;In any case, you should start by troubleshooting Identity Collector:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/Identity_Awareness_Clients_Admin_Guide/Content/Topics-IA-Clients-AG/Identity-Collector-Debug.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/Identity_Awareness_Clients_Admin_Guide/Content/Topics-IA-Clients-AG/Identity-Collector-Debug.htm&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 15:48:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/251907#M42142</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-06-24T15:48:33Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awarness question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/251908#M42143</link>
      <description>&lt;P&gt;Myabe this one:&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk114096" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk114096&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 15:51:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/251908#M42143</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2025-06-24T15:51:38Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awarness question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/251909#M42144</link>
      <description>&lt;P&gt;If you run pdp update all command, what does it show?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 16:11:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/251909#M42144</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-24T16:11:36Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awarness question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/251941#M42145</link>
      <description>&lt;P&gt;Verify the AD Permission as well&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk43874" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk43874&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk93938" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk93938&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2025 06:33:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/251941#M42145</guid>
      <dc:creator>garrod</dc:creator>
      <dc:date>2025-06-25T06:33:11Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awarness question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/251962#M42149</link>
      <description>&lt;P&gt;it's seemes issue related to&amp;nbsp;&lt;SPAN data-teams="true"&gt;domain controller&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2025 13:09:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/251962#M42149</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2025-06-25T13:09:38Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awarness question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/252064#M42177</link>
      <description>&lt;P&gt;pdp update all&lt;BR /&gt;output &amp;gt; update operation may take a few minutes&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2025 14:47:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/252064#M42177</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2025-06-26T14:47:43Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awarness question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/252065#M42178</link>
      <description>&lt;P&gt;So command did work, but not sure if it did much. Does pdp monitor user work for ANY user at all?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2025 14:57:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/252065#M42178</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-26T14:57:34Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awarness question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/252066#M42179</link>
      <description>&lt;P&gt;take for example a user john.&lt;BR /&gt;qunado i do the:&lt;BR /&gt;pdp m u john&lt;BR /&gt;sometimes i get&lt;BR /&gt;sometimes i don't &lt;BR /&gt;sometimes i get an incorrect ip..&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2025 14:59:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/252066#M42179</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2025-06-26T14:59:39Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awarness question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/252067#M42180</link>
      <description>&lt;P&gt;What about any other user?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2025 15:04:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/252067#M42180</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-26T15:04:38Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awarness question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/252068#M42181</link>
      <description>&lt;P&gt;it's randomic but same behavior&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2025 15:05:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/252068#M42181</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2025-06-26T15:05:59Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awarness question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/252069#M42182</link>
      <description>&lt;P&gt;Have you tried cprestart or reboot? Or if its a cluster,a failover?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2025 15:08:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/252069#M42182</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-26T15:08:21Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awarness question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/252070#M42183</link>
      <description>&lt;P&gt;yes no fortune&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2025 15:09:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/252070#M42183</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2025-06-26T15:09:10Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awarness question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/252071#M42184</link>
      <description>&lt;P&gt;Here is what TAC gave me while ago for IA debugs, maybe give it a go and see if anything useful is there.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;(•)•) Identity awareness debugs&lt;BR /&gt;# cd $FWDIR/log&lt;BR /&gt;# rm pdpd.elg.*&lt;BR /&gt;# echo "=debug_start=" &amp;gt;&amp;gt; $FWDIR/log/pdpd.elg&lt;BR /&gt;(•) To turn pdp debug on:&lt;BR /&gt;# adlog a d on&lt;BR /&gt;# pdp debug on&lt;BR /&gt;# pep debug on&lt;BR /&gt;# pdp debug set all all&lt;BR /&gt;(•) Replicate the issue&lt;BR /&gt;(•) To turn them off:&lt;BR /&gt;# adlog a d off&lt;BR /&gt;# pdp debug unset all all&lt;BR /&gt;# pdp debug off&lt;BR /&gt;# pep debug off&lt;BR /&gt;# pdp d reset&lt;BR /&gt;# pep d unset all all&lt;BR /&gt;Collect debug:&lt;BR /&gt;$FWDIR/log/pdpd.elg&lt;BR /&gt;# tar zcvf pdpd_debugs.tgz pdpd.elg*&lt;BR /&gt;# tar zcvf pepd_debugs.tgz pepd.elg*&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2025 15:26:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awarness-question/m-p/252071#M42184</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-26T15:26:57Z</dc:date>
    </item>
  </channel>
</rss>

