- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Without knowing more about your environment, which includes:
It's hard to know where to start on this.
The actual log in/out events, which are shown in the screenshot provided, should be reviewed to see if they provide any clues.
You will need to see the full log card.
This is the IA debug TAC gave me while back, so you can definitely run it and see if it helps. I do agree with Phoneboy that we need full log details, just blour out any sentisive data.
Andy
debugs:
# cd $FWDIR/log
# rm pdpd.elg.*
# echo "=debug_start=" >> $FWDIR/log/pdpd.elg
(•) To turn pdp debug on:
# adlog a d on
# pdp debug on
# pep debug on
# pdp debug set all all
(•) Replicate the issue
(•) To turn them off:
# adlog a d off
# pdp debug unset all all
# pdp debug off
# pep debug off
# pdp d reset
# pep d unset all all
Collect debug:
$FWDIR/log/pdpd.elg
# tar zcvf pdpd_debugs.tgz pdpd.elg*
# tar zcvf pepd_debugs.tgz pepd.elg*
Hello everyone,
I've learned something new: the "pdp control sync" command fixes my problem, and it works again immediately. Now, of course, the question is why the database isn't replicating properly in the cluster system with R81.20 Take 113. Are there any settings or something similar?
Just tried it on both R81.20 and R82. but get below...
Andy
[Expert@CP-FW-01:0]# pep control sync
Command: root->control
Unknown option: sync
Available options:
portal_dual_stack - portal dual stack (IPv4 and IPv6) support
extended_info_storage - should the PEP store extended identities info for debugging or not
tasks_manager - the task manager menu
kbuf_cache - Kbuf cache configuration
gbuf_cache - Gbuf cache configuration
identity_cache_mode - Identity Cache mode configuration
[Expert@CP-FW-01:0]#
sorry : pdp control sync
Thats better : - )
[Expert@CP-FW-01:0]# pdp control sync
a sync message will be sent to relevant gateways
[Expert@CP-FW-01:0]#
How often though?
Andy
today like 10 times.
That is not normal, for sure. I would open TAC case to investigate.
Running the command periodically via cron might be a good idea in the short term while you investigate the issue with TAC,
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 66 | |
| 19 | |
| 13 | |
| 12 | |
| 11 | |
| 9 | |
| 9 | |
| 7 | |
| 7 | |
| 7 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY