<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PDP Identity Sharing mode in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/PDP-Identity-Sharing-mode/m-p/158324#M1190</link>
    <description>&lt;P&gt;In the past, it was also highly recommened to clear the IDA tables and restart all involved pdpd and pepd after changing the sharing method from smart-pull to push.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk170516" target="_self"&gt;sk170516&lt;/A&gt;&amp;nbsp;is unrelated to your topic, but shows one example of how to clear these tables (and restart the processes).&lt;/P&gt;
&lt;P&gt;Not sure, if it is still needed to today, so you better go through this together with TAC as suggested by Peter and Val.&lt;/P&gt;</description>
    <pubDate>Wed, 28 Sep 2022 13:26:32 GMT</pubDate>
    <dc:creator>Tobias_Moritz</dc:creator>
    <dc:date>2022-09-28T13:26:32Z</dc:date>
    <item>
      <title>PDP Identity Sharing mode</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/PDP-Identity-Sharing-mode/m-p/158143#M1182</link>
      <description>&lt;P&gt;My apologies if the answer is documented somewhere else in this forum. I just can't find it.&lt;/P&gt;&lt;P&gt;We have a Maestro platform in which we run several security groups with VSLS. A long time ago we had help from TAC to change the PDP mode in security group 1 from Pull to Push. For a couple of reasons pull just doesn't work for us. Now we must implement the same change to security group 3. However, the steps performed by TAC was not documented in the case notes. The only thing we know for certains was that the GuiDBEdit tools was used.&lt;/P&gt;&lt;P&gt;I have search for a SK that could describe what actions need to taken.&lt;/P&gt;&lt;P&gt;We are running version R81.10 Take 66.&lt;/P&gt;&lt;P&gt;PDPs (both access and aggregation layers) are external the to Maestro by running as separate VMs in VMware datacenter. Works well in security group 1 with Push mode configured. Users are identified with the help of the ID Agent which is installed on every workstation and laptop. Agents talk to the PDP access layer, which by a PDP broker shares information to the PDP aggregation layer, which pushes identites to the PEP on each gateway.&lt;/P&gt;&lt;P&gt;Can anyone point out instructions where in GuiDBEdit this can be changed in the same way in SG3?&lt;/P&gt;&lt;P&gt;I've already read this: &lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Identity-sharing-how-to-change-modes/m-p/62906#" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Identity-sharing-how-to-change-modes/m-p/62906#&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Big thanks,&lt;/P&gt;&lt;P&gt;Fredrik&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 10:47:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/PDP-Identity-Sharing-mode/m-p/158143#M1182</guid>
      <dc:creator>FredrikV</dc:creator>
      <dc:date>2022-09-27T10:47:31Z</dc:date>
    </item>
    <item>
      <title>Re: PDP Identity Sharing mode</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/PDP-Identity-Sharing-mode/m-p/158147#M1183</link>
      <description>&lt;P&gt;It is the best to take it with TAC&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 11:35:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/PDP-Identity-Sharing-mode/m-p/158147#M1183</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-09-27T11:35:08Z</dc:date>
    </item>
    <item>
      <title>Re: PDP Identity Sharing mode</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/PDP-Identity-Sharing-mode/m-p/158148#M1184</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/177"&gt;@Peter_Elmer&lt;/a&gt;&amp;nbsp;what do you think?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 11:37:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/PDP-Identity-Sharing-mode/m-p/158148#M1184</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-09-27T11:37:54Z</dc:date>
    </item>
    <item>
      <title>Re: PDP Identity Sharing mode</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/PDP-Identity-Sharing-mode/m-p/158149#M1185</link>
      <description>&lt;P&gt;Got it&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 11:42:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/PDP-Identity-Sharing-mode/m-p/158149#M1185</guid>
      <dc:creator>FredrikV</dc:creator>
      <dc:date>2022-09-27T11:42:32Z</dc:date>
    </item>
    <item>
      <title>Re: PDP Identity Sharing mode</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/PDP-Identity-Sharing-mode/m-p/158154#M1186</link>
      <description>&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk175587&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;sk175587: Identity Based Access Control and Threat Prevention - Design Guidelines - Quantum Maestro&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 12:07:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/PDP-Identity-Sharing-mode/m-p/158154#M1186</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-09-27T12:07:51Z</dc:date>
    </item>
    <item>
      <title>Re: PDP Identity Sharing mode</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/PDP-Identity-Sharing-mode/m-p/158159#M1187</link>
      <description>&lt;P&gt;I believe it should be something like this (Unfortunately I haven't possibility to check it - it's from my personal notes):&lt;/P&gt;&lt;P&gt;Network Objects -&amp;gt; network_objects -&amp;gt; [Name of PDP cluster or name of VS] -&amp;gt; identity_aware_blade -&amp;gt; publish_method: change from smart_pull to push&lt;/P&gt;&lt;P&gt;You can check it for existing configuration VS's in SecGrp and PDP cluster).&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Daniel.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 13:09:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/PDP-Identity-Sharing-mode/m-p/158159#M1187</guid>
      <dc:creator>Daniel_Szydelko</dc:creator>
      <dc:date>2022-09-27T13:09:35Z</dc:date>
    </item>
    <item>
      <title>Re: PDP Identity Sharing mode</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/PDP-Identity-Sharing-mode/m-p/158179#M1189</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/53449"&gt;@FredrikV&lt;/a&gt;,&amp;nbsp; - cc thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;for pining to this post !&lt;/P&gt;
&lt;P&gt;as mentioned by&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;you may want to study &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk175587" target="_blank" rel="noopener"&gt;sk175587&lt;/A&gt;. It is linked form the Maestro Administration Guide.&lt;/P&gt;
&lt;P&gt;Due to the load balancing of Maestro performed on inbound connections you need to work with &lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_IdentityAwareness_AdminGuide/Topics-IDAG/Identity-Awareness-Config-Identity-Sharing.htm?TocPath=Identity%20Awareness%20Environment%7C_____1#Identity_Sharing" target="_blank" rel="noopener"&gt;Push ID Sharing&lt;/A&gt; method. Changing from SmartPull to Push needs to be done with the support of TAC or PS to avoid misconfigurations.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'll talk to R&amp;amp;D to see if the procedure can get published but I can't promise anything for now.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For Identity Based guidelines you may want to work with your local presales office. Further reading that may help are &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk179544" target="_blank" rel="noopener"&gt;sk179544&lt;/A&gt; and &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk170765&amp;amp;srcFavorites=favorites" target="_blank" rel="noopener"&gt;sk170765&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;best regards&lt;/P&gt;
&lt;P&gt;pelmer&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 14:50:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/PDP-Identity-Sharing-mode/m-p/158179#M1189</guid>
      <dc:creator>Peter_Elmer</dc:creator>
      <dc:date>2022-09-27T14:50:11Z</dc:date>
    </item>
    <item>
      <title>Re: PDP Identity Sharing mode</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/PDP-Identity-Sharing-mode/m-p/158324#M1190</link>
      <description>&lt;P&gt;In the past, it was also highly recommened to clear the IDA tables and restart all involved pdpd and pepd after changing the sharing method from smart-pull to push.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk170516" target="_self"&gt;sk170516&lt;/A&gt;&amp;nbsp;is unrelated to your topic, but shows one example of how to clear these tables (and restart the processes).&lt;/P&gt;
&lt;P&gt;Not sure, if it is still needed to today, so you better go through this together with TAC as suggested by Peter and Val.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 13:26:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/PDP-Identity-Sharing-mode/m-p/158324#M1190</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2022-09-28T13:26:32Z</dc:date>
    </item>
    <item>
      <title>Re: PDP Identity Sharing mode</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/PDP-Identity-Sharing-mode/m-p/158504#M1192</link>
      <description>&lt;P&gt;Thanks everyone for your valuable advices!&lt;/P&gt;&lt;P&gt;We successfully made the change this morning, as per instructions provided both by TAC and PMs. It's always nice when actions can be confirmed from multiply resources.&lt;/P&gt;&lt;P&gt;Br,&lt;/P&gt;&lt;P&gt;Fredrik&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 07:50:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/PDP-Identity-Sharing-mode/m-p/158504#M1192</guid>
      <dc:creator>FredrikV</dc:creator>
      <dc:date>2022-09-30T07:50:55Z</dc:date>
    </item>
    <item>
      <title>Re: PDP Identity Sharing mode</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/PDP-Identity-Sharing-mode/m-p/158505#M1193</link>
      <description>&lt;P&gt;Yes, that's correct. And not to be forgotten - reinstallation of policies and restarting pdp and pep daemons.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 07:56:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/PDP-Identity-Sharing-mode/m-p/158505#M1193</guid>
      <dc:creator>FredrikV</dc:creator>
      <dc:date>2022-09-30T07:56:22Z</dc:date>
    </item>
    <item>
      <title>Re: PDP Identity Sharing mode</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/PDP-Identity-Sharing-mode/m-p/158506#M1194</link>
      <description>&lt;P&gt;Yes. We did both methods actually. On a lab VS without load I only restarted the PEP daemon without emptying any tables. Looks like it did the trick anyways. But still better to be sure. Did clear the tables on the more critical VS's.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 08:00:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/PDP-Identity-Sharing-mode/m-p/158506#M1194</guid>
      <dc:creator>FredrikV</dc:creator>
      <dc:date>2022-09-30T08:00:51Z</dc:date>
    </item>
    <item>
      <title>Re: PDP Identity Sharing mode</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/PDP-Identity-Sharing-mode/m-p/158507#M1195</link>
      <description>&lt;P&gt;Thank you Peter for confirming that within the Maestro platform.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 08:02:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/PDP-Identity-Sharing-mode/m-p/158507#M1195</guid>
      <dc:creator>FredrikV</dc:creator>
      <dc:date>2022-09-30T08:02:14Z</dc:date>
    </item>
  </channel>
</rss>

