That should work without any problems. We, for example, have multi-domain management and therefore need domain layer PDP devices in every CMA to propagate the sessions from core layer PDP devices. The domain layer PDPs then propagate session information via identity sharing to the enforcing gateways (pep).
The communication relationships are configured in identity_broker. C, and to ensure that the whole thing is connected, firewall rules are of course also required for the devices involved. The punlishers connect to the subscribers via an SSL channel, for which a certificate is also defined in the gateway object, identity awareness section.
This should also work in your case with devices on different management servers.
fyi: As far as I know, Checkpoint has announced a significant change for R 82.10 or something? I still need to look at the details. This could simplify the whole thing significantly.
hope that helps
P.S.: One small correction. The brokers are not hosted on the management server. They run locally on the gateway, and identity_broker.C is also located on the gateway.
The gateway object is managed as usual on the management server or the CMA. As mentioned above, the broker certificate is also managed here. You can import certificates that you have created yourself or purchased, although you do not need purchased certificates in the case of broker.
and now to something completely different - CCVS, CCAS, CCTE, CCCS, CCSM elite