Try running these on the gateway:
pdp monitor user (username)
pdp monitor ip (IP address)
pdp monitor groups (groupname) - Shows all current known members of (groupname)
These commands will show the user/IP mappings and all group memberships cached on the gateway sliced and diced different ways. My understanding is that once a gateway forms a mapping (whether doing it locally via pdpd or getting it from the IC), the gateway will immediately query the domain for the group memberships and place them in the IA cache which is visible with the above commands.
--
CheckMates Break Out Sessions Speaker
CPX 2019 Las Vegas & Vienna - Tuesday@13:30
Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com