<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 1550 identity sharing and drops from failed identity lookups? in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-identity-sharing-and-drops-from-failed-identity-lookups/m-p/90128#M3811</link>
    <description>&lt;P&gt;we spent some time with TAC on this , but they weren't able to replicate in the LAB.&lt;/P&gt;&lt;P&gt;we decided to deploy a 3100 appliance with full Gaia and compatible with identity collector then to keep working on this. Sounds like it wasn't isolated to our environment though - we had 1450's with the identical configuration that worked fine, but the 1550&amp;nbsp; model just seemed to be problematic as soon as we deployed it.&lt;/P&gt;</description>
    <pubDate>Tue, 30 Jun 2020 03:09:22 GMT</pubDate>
    <dc:creator>Shawn_Fletcher</dc:creator>
    <dc:date>2020-06-30T03:09:22Z</dc:date>
    <item>
      <title>1550 identity sharing and drops from failed identity lookups?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-identity-sharing-and-drops-from-failed-identity-lookups/m-p/72575#M2850</link>
      <description>&lt;P&gt;I've deployed 2 1550 appliances so far with permanent vpn tunnels to 21800. Both have required rules to bypass app control to get working due to errors like this on fw ctl zedebug drop&lt;/P&gt;&lt;P&gt;Example - this drops&lt;/P&gt;&lt;P&gt;@;745809;26Nov2019 20:32:25.035701;[cpu_0];[fw4_0];fw_log_drop_ex: Packet proto=17 172.18.50.12:64344 -&amp;gt; Pxxx.xxx.xxx.xxx:53 dropped by fwhold_expires Reason: held chain expired;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even with bypass rules for App control i constantly get identity fetch failed which appears to drop some traffic - even though SmartLog doesnt reflect.... (i'm having VOIP issues, this example below is a VOIP phone/VOIP server communication)&lt;/P&gt;&lt;P&gt;@;10284017;[cpu_3];[fw4_3];[ERROR]: ida_cmi_async_fetch_log_cb: the identity fetch failed;&lt;BR /&gt;@;10284317;[cpu_0];[fw4_0];[ERROR]: ida_cmi_async_fetch_log_cb: the identity fetch failed;&lt;BR /&gt;@;10284317;[cpu_0];[fw4_0];[ERROR]: ida_cmi_async_fetch_log_cb: the identity fetch failed;&lt;BR /&gt;@;10284349;[cpu_1];[fw4_1];[IPxxx.xxx.xxx.xxx:5252 -&amp;gt; 172.18.20.144:5200] [ERROR]: ida_cmi_async_fetch_log_cb: the identity fetch failed;&lt;BR /&gt;@;10284349;[cpu_1];[fw4_1];[IPxxx.xxx.xxx.xxx:5252 -&amp;gt; 172.18.20.144:5200] [ERROR]: ida_cmi_async_fetch_log_cb: the identity fetch failed;&lt;BR /&gt;@;10284349;[cpu_1];[fw4_1];[IPPxxx.xxx.xxx.xxx:5252 -&amp;gt; 172.18.20.144:5200] [ERROR]: ida_cmi_async_fetch_log_cb: the identity fetch failed;&lt;BR /&gt;@;10284349;[cpu_3];[fw4_3];[ERROR]: ida_cmi_async_fetch_log_cb: the identity fetch failed;&lt;BR /&gt;@;10284349;[cpu_3];[fw4_3];[ERROR]: ida_cmi_async_fetch_log_cb: the identity fetch failed;&lt;BR /&gt;@;10284349;[cpu_3];[fw4_3];[ERROR]: ida_cmi_async_fetch_log_cb: the identity fetch failed;&lt;BR /&gt;@;10284349;[cpu_3];[fw4_3];[ERROR]: ida_cmi_async_fetch_log_cb: the identity fetch failed;&lt;BR /&gt;@;10284374;[cpu_2];[fw4_2];[ERROR]: ida_cmi_async_fetch_log_cb: the identity fetch failed;&lt;BR /&gt;@;10284374;[cpu_2];[fw4_2];[ERROR]: ida_cmi_async_fetch_log_cb: the identity fetch failed;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The idea would be the 21800 central gateway uses Identity Collector Server with ISE to get identities and then share them to remote site gateways (R80.20 embedded doesn't support identity collector - that would have been nice)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;on 21800 (running R80.20 jumbo 103&amp;nbsp;&lt;/P&gt;&lt;P&gt;pdp connections pep shows&lt;/P&gt;&lt;P&gt;| Outgoing | IPXXX.XXXX | 15105 | STJ-BrantfordKC | Single Gateway | Disconnected | Remote | No |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;on 1550 - some network info has come over - so it must have connected at some point&lt;/P&gt;&lt;P&gt;pep show network pdp&lt;BR /&gt;Trying to run main_pep&lt;BR /&gt;--------------------------------------------------------&lt;BR /&gt;| Network | Mask | Related PDPs |&lt;BR /&gt;--------------------------------------------------------&lt;BR /&gt;| 172.28.138.0 | 255.255.255.0 | &amp;lt;21800IP,0&amp;gt;; |&lt;BR /&gt;--------------------------------------------------------&lt;/P&gt;&lt;P&gt;(and many more network lines)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;pep show network registration&lt;BR /&gt;Trying to run main_pep&lt;BR /&gt;------------------&lt;BR /&gt;| Network | Mask |&lt;BR /&gt;------------------&lt;/P&gt;&lt;P&gt;nothing&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;pep sh user all&lt;BR /&gt;Trying to run main_pep&lt;BR /&gt;Command: root-&amp;gt;show-&amp;gt;user-&amp;gt;all&lt;BR /&gt;ID (PDP; UID) Username@Machine CID (IP, PacketID) PT&lt;BR /&gt;=============================================================================================================&lt;/P&gt;&lt;P&gt;nothing&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So far nothing but issues with 1550's compared to 1450's... a bit dissapointed....&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyways open to any ideas since SMB appliance issues never seem to be a priority for TAC... thx&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2020 23:42:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-identity-sharing-and-drops-from-failed-identity-lookups/m-p/72575#M2850</guid>
      <dc:creator>Shawn_Fletcher</dc:creator>
      <dc:date>2020-01-17T23:42:00Z</dc:date>
    </item>
    <item>
      <title>Re: 1550 identity sharing and drops from failed identity lookups?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-identity-sharing-and-drops-from-failed-identity-lookups/m-p/90118#M3809</link>
      <description>&lt;P&gt;Hi Shawn,&lt;/P&gt;&lt;P&gt;Did you get a resolution to this issue?&amp;nbsp; We seem to be having a very similar problem with some 1550s not learning IDs from a sharing gateway.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Greg&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2020 00:14:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-identity-sharing-and-drops-from-failed-identity-lookups/m-p/90118#M3809</guid>
      <dc:creator>Greg_Harbers</dc:creator>
      <dc:date>2020-06-30T00:14:55Z</dc:date>
    </item>
    <item>
      <title>Re: 1550 identity sharing and drops from failed identity lookups?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-identity-sharing-and-drops-from-failed-identity-lookups/m-p/90128#M3811</link>
      <description>&lt;P&gt;we spent some time with TAC on this , but they weren't able to replicate in the LAB.&lt;/P&gt;&lt;P&gt;we decided to deploy a 3100 appliance with full Gaia and compatible with identity collector then to keep working on this. Sounds like it wasn't isolated to our environment though - we had 1450's with the identical configuration that worked fine, but the 1550&amp;nbsp; model just seemed to be problematic as soon as we deployed it.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2020 03:09:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-identity-sharing-and-drops-from-failed-identity-lookups/m-p/90128#M3811</guid>
      <dc:creator>Shawn_Fletcher</dc:creator>
      <dc:date>2020-06-30T03:09:22Z</dc:date>
    </item>
    <item>
      <title>Re: 1550 identity sharing and drops from failed identity lookups?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-identity-sharing-and-drops-from-failed-identity-lookups/m-p/90129#M3812</link>
      <description>&lt;P&gt;Thanks for the reply,&lt;/P&gt;&lt;P&gt;the customer has purchased about 10 of these appliances, so replacing with 3100s is not an option. And yes, they have about 30+ 1450/1490s working just fine with the same configuration&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2020 03:14:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-identity-sharing-and-drops-from-failed-identity-lookups/m-p/90129#M3812</guid>
      <dc:creator>Greg_Harbers</dc:creator>
      <dc:date>2020-06-30T03:14:53Z</dc:date>
    </item>
    <item>
      <title>Re: 1550 identity sharing and drops from failed identity lookups?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-identity-sharing-and-drops-from-failed-identity-lookups/m-p/90130#M3813</link>
      <description>&lt;P&gt;I know this is supposed to happen automatically but what about if you add both gateways' external IPs to VPN encryption domain ?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2020 03:34:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-identity-sharing-and-drops-from-failed-identity-lookups/m-p/90130#M3813</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-06-30T03:34:23Z</dc:date>
    </item>
    <item>
      <title>Re: 1550 identity sharing and drops from failed identity lookups?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-identity-sharing-and-drops-from-failed-identity-lookups/m-p/96191#M4143</link>
      <description>&lt;P&gt;FYI, after some time working with Check Point R&amp;amp;D, they eventually managed to replicate the issue within their environment. From that, we have received build 477 of R80.20.10 for the 1500s and this has resolved the Identity Sharing issue.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Sep 2020 10:40:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-identity-sharing-and-drops-from-failed-identity-lookups/m-p/96191#M4143</guid>
      <dc:creator>Greg_Harbers</dc:creator>
      <dc:date>2020-09-07T10:40:23Z</dc:date>
    </item>
  </channel>
</rss>

