- Products
- Learn
- Local User Groups
- Partners
- More
Scaling Check Point Automation with Arodonata
7 October @ 5pm CET / 11am EDT
AI Security Masters
LGTM: Bypassing an LLM Build Gate
When Prompt Injection Fails
What's New in Check Point SASE
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
CheckMates Go:
Half is Not Enough
Hi All,
I recently installed IDC on a separate Window server and configured it as per the Guide.
I have connected to 6 of my DC's and its receiving events fine. Then i connected one Firewall which is in the same virtual Network and it is receiving all the events and i see users and Machine identities in my firewall.
FW (identity source)----->Identity collector
Now I have added another firewall and it is connected and IDC shows connected and Events are being sent . On firewall, I dont see any user/Machine identities getting updated .
Firewall (Identity source)----->VPN site to site----->Identity collector
Is there something else I have to do for Events to go over VPN tunnel to my Firewalls that is trying to get identities from IDC ? Because if its is not over VPN tunnel , its working fine.
Both Firewalls are R81.20 and have same configuration and IDC shows both connected and events are being sent and I do see numbers increase in IDC.
That 100% looks right to me. I would open TAC case about it to see what they say.
Andy
Maybe a silly question, but did you make sure windows fw is off on that machine?
Andy
Hi,
Yes it is off, since one firewall is working fine.
K, I see what you meant in your post. So, the one that fails, the difference is it goes over vpn tunnel. Can you do capture and make sire IC ip is not getting dropped? Run fw monitor and then in other ssh window run zdebug
So say IC ip is 10.10.10.10, do something like this:
ssh 1 -> fw monitor -e "accept host(10.10.10.10);"
ssh 2 -> fw ctl zdebug + drop | grep 10.10.10.10
Hi,
I just confirmed that traffic indeed is coming at port 443 and there is no drop in the traffic. I do see vpn logs too and nothing looks out of place. All connectivity looks fine 😞
I would try restart IC machine to see if it makes any difference. Maybe also run pdp update all on the problematic gateway.
Andy
That 100% looks right to me. I would open TAC case about it to see what they say.
Andy
One thing I would do is maybe try do IA debugs on the fw and see what gives.
commands are pep debug on and pdp debug on (off to turn off). Once done, check $FWDIR/dir log for pep and pdp log files.
Hope that helps.
Andy
Thank you all for your replies. am heading for my vacation for next week. I will open tac case now once am back 🙂
Have a nice vacation!
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 33 | |
| 8 | |
| 6 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 | |
| 3 |
Thu 01 Oct 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point WAF | Preventing minus-zero-day attacksTue 06 Oct 2026 @ 12:00 PM (ACDT)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus APACTue 06 Oct 2026 @ 03:00 PM (CEST)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus EMEAThu 01 Oct 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point WAF | Preventing minus-zero-day attacksTue 06 Oct 2026 @ 12:00 PM (ACDT)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus APACTue 06 Oct 2026 @ 03:00 PM (CEST)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus EMEATue 06 Oct 2026 @ 02:00 PM (EDT)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus AMERAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY