- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
hi,
I have come across a bit of a challenge with identity Awareness.
We are using Identity Collector and identity sharing, with 4 gatewas acting as PDP, and several others as PEP.
A new access role was recently created, with access rule on a PEP gateway. this is currently in test, and will be moved to production if successful
For one user, this works just fine, and he gets the correct access.
For other users, they do not hit this access rule at all.
When i run a pep show user query usr <username>, i see that the new access role is not associated with the user at all.
Have tried running the pdp sync and pdp update on the PDP gateway closest to the PEP gateway, but the new access role is not associated at all with the user.
Is this because of the cache on the PDP gateway, as the users will log on again before the 24 hours expire, thus the cached identity is reused?
What would be a potential consequence if we reduce the time limit on the cache before entries are deleted?
The environment is R81.10 with jumbo t66 on top, and there are only appliances in the environment.
Any input here would be appreciated:)
Is the Access Role in use in any policy on the other gateways?
Not sure how the PDP on the remote gateways will handle roles it does not have any rules for.
This might require a TAC case to get to the bottom of.
https://help.checkpoint.com
hi,
I actually didnt check. The pdp and pep gateways are actually connected( they are the internal and external cluster for the customer),
So, it could be that the access rule is not set on the PDP gateway? But is that a requirement in order for the access rule to work on the PEP gateway? if so, i can check this, and copy the rule over if necessary.
update:
The access role is succesfully synced over to the PEP gateway, so that is good.
However, why would it take 48 hours in order for this to sync properly?
That's unusual.
Recommend a TAC case to investigate: https://help.checkpoint.com
Hello,
we are facing similiar problem, did you fix it?
an access role in a pep gateway is working only from some users (same vlan, same domain), other user are not synced from PDP gateway, where the identity is corrected associated
Maybe this is related? TAC gave us this for similar issue with a customer...
Andy
https://support.checkpoint.com/results/sk/sk181429
thanks Andy,
no, on pdp gateway the identity is ok
TAC Case araised
Let us know what they say.
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 22 | |
| 20 | |
| 16 | |
| 5 | |
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY