- Products
- Learn
- Local User Groups
- Partners
- More
Introduction to Lakera:
Securing the AI Frontier!
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hello
We manage 50+ gw with full meshed IA sharing.
We face lot of isues with IA.
Some random IA not propagated accross gw, some random IA agents not able to connect to their local gw...
Something that improve the behavior a little bit is a cronjob to kill pep and pdp every night...
We think about centralising IA on a dedicated gw, so IA agents connect to this specific gw and it redistribute IA to all gw.
It's a big change that cannot be fully tested outside production and we are a little bit afraid things get worse than now.
How do you folks manage IA at scale?
Do you have to kill pep and pdp every night too?
Do you centralise IA to a single sharing gw?
Thanks for your advises.
We are slowly migrating to this setup and it looks like our issues disappear.
Checkpoint should really highlight the usage of very centric PDP to avoid IA sharing issues as soon as 2 firewalls are involved.
sk88520: Best Practices - Identity Awareness Large Scale Deployment
Yes, I read that.
I want to know administator feedback about IA sharing in general, this solution or others they may have deployed to fix IA.
R81.20 has some relevant IA enhancements...
Are you using any of the following today and what version are the current Gateways?
- Identity Collector
- Identity Broker
- Dedicated PDPs
We are currently running R81.10 HFA110 on every gw.
We'll upgrade to R81.20 as soon as we get a maintenance windows.
Hello,
Please check not resolved issues in IA for R81.20:
BR,
Daniel.
Hello,
we use dedicated PDP Brokers. The firewall itselfs only do the pep enforcement. We completly seperated these two services from each other. These PDP Brokers are full meshed to share all identies with each other. The peps only consume the identies from their local PDP Broker.
We don't need to kill pep / pdp every night.
We setup a centralised IA PDP Broker for every region.
We switched from our full meshed design to PDP Brokers in 2021. I draw our design and uploaded it here:
If you want more informations, feel free to contact me via private message.
Best regards
Hello,
Thanks for sharing.
Your setup make sense to us. We will think about making something similar.
Thanks mate!
We are slowly migrating to this setup and it looks like our issues disappear.
Checkpoint should really highlight the usage of very centric PDP to avoid IA sharing issues as soon as 2 firewalls are involved.
Hi @ProxyOps
Very interesting design!
Just wondering if your PDP Broker are working with Cluster_XL or not ? Does Cluster_XL synchronize the IA tables ?
Today we have a central design with IA Sharing accross multiples site which is just working fine. Problem is to find window maintenance to upgrade this central IA gateway.
This central Gateway is doing PDP for all users and then share identity with PEP to all remote GW.
Thank you
Hi @CP-NDA
we are running our PDP Broker as Clusters (Cluster_XL) active-standby on VMs.
Our PDP Brokers are running R81 currently are cluster_xl is not snycing the relevant tables for a interruption free failover.
When we do a failover the PDP Broker has to sync from scratch again with all over PDP Brokers.
I checked the R81.20 release noted and maybe something was improved here?
"Improved resiliency, scalability, and stability for PDPs and Identity Broker. Additional threads handle authentication and authorization flows."
I know cluster_xl is syncing some IA tables for PEP but I am not able to find a sk for that.
I have to admit, that we update the PDP Broker Gateways only if required as we need them to be as stable as possible.
Best regards
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
12 | |
12 | |
9 | |
7 | |
7 | |
6 | |
6 | |
5 | |
5 | |
5 |
Tue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY