- Products
- Learn
- Local User Groups
- Partners
- More
Check Point WAF TechTalk:
Introduction and New Features
AI Security Masters E6: When AI Goes Wrong -
Hallucinations, Jailbreaks, and the Curious Behavior of AI Agents
Ink Dragon: A Major Nation-State Campaign
Watch HereAI Security Masters E5:
Powering Prevention: The AI Driving Check Point’s ThreatCloud
CheckMates Go:
CheckMates Fest
Users are assigned to the access roles, but the IA system is unable to recognize their accounts within the GRP AD groups that have permissions to access the resources.
how can i resolve this. if i do pdp monitor user Jhon123 the output it's empty
Thanks
Please share additional details about the environment including version/jumbo, adquery or identity collector etc
Have you validated the settings of the account unit, how many are configured ?
Hi @Chris_Atkinson
R81.20 JHF 53
identity collector.
all criteria should match the AR, the AR is configured to use AD groups
We need a lot more information like:
Generally, though, groups come from two places:
For troubleshooting, see https://support.checkpoint.com/results/sk/sk183118
Hi @PhoneBoy as i said:
user is not known by the PDP Broker, Identity Collector, we performend a restart of the Identity collector service on the server but nothing change .
the sk doesn't exist
Sorry, didn't notice that SK was internal.
In any case, you should start by troubleshooting Identity Collector: https://sc1.checkpoint.com/documents/Identity_Awareness_Clients_Admin_Guide/Content/Topics-IA-Client...
Myabe this one:
https://support.checkpoint.com/results/sk/sk114096
If you run pdp update all command, what does it show?
Andy
it's seemes issue related to domain controller
pdp update all
output > update operation may take a few minutes
So command did work, but not sure if it did much. Does pdp monitor user work for ANY user at all?
Andy
take for example a user john.
qunado i do the:
pdp m u john
sometimes i get
sometimes i don't
sometimes i get an incorrect ip..
What about any other user?
Andy
it's randomic but same behavior
Have you tried cprestart or reboot? Or if its a cluster,a failover?
Andy
yes no fortune
Here is what TAC gave me while ago for IA debugs, maybe give it a go and see if anything useful is there.
Andy
(•)•) Identity awareness debugs
# cd $FWDIR/log
# rm pdpd.elg.*
# echo "=debug_start=" >> $FWDIR/log/pdpd.elg
(•) To turn pdp debug on:
# adlog a d on
# pdp debug on
# pep debug on
# pdp debug set all all
(•) Replicate the issue
(•) To turn them off:
# adlog a d off
# pdp debug unset all all
# pdp debug off
# pep debug off
# pdp d reset
# pep d unset all all
Collect debug:
$FWDIR/log/pdpd.elg
# tar zcvf pdpd_debugs.tgz pdpd.elg*
# tar zcvf pepd_debugs.tgz pepd.elg*
Verify the AD Permission as well
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 11 | |
| 9 | |
| 8 | |
| 7 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 |
Tue 24 Mar 2026 @ 04:00 PM (CET)
Maestro Masters EMEA: Hyperscale Firewall Architectures and OptimizationTue 24 Mar 2026 @ 03:00 PM (EDT)
Maestro Masters Americas: Hyperscale Firewall Architectures and OptimizationTue 24 Mar 2026 @ 06:00 PM (COT)
San Pedro Sula: Spark Firewall y AI-Powered Security ManagementThu 26 Mar 2026 @ 06:00 PM (COT)
Tegucigalpa: Spark Firewall y AI-Powered Security ManagementTue 24 Mar 2026 @ 04:00 PM (CET)
Maestro Masters EMEA: Hyperscale Firewall Architectures and OptimizationTue 24 Mar 2026 @ 03:00 PM (EDT)
Maestro Masters Americas: Hyperscale Firewall Architectures and OptimizationTue 07 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Check Point WAF and IO River: Multi-CDN Security in ActionWed 08 Apr 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: The Cloud Firewall with near 100% Zero Day prevention - In 7 LanguagesTue 24 Mar 2026 @ 06:00 PM (COT)
San Pedro Sula: Spark Firewall y AI-Powered Security ManagementThu 26 Mar 2026 @ 06:00 PM (COT)
Tegucigalpa: Spark Firewall y AI-Powered Security ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY