- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
I've had some issues with our Identity Collectors and have tried to restart the "pdpd" and "pepd" processes with the following commands:
# fw kill pdpd
# fw kill pepd
They both seem to be running again and the Identity Collectors are receiving events from our AD and sending to the firewall. Also the firewall says that it is connected as you can see below:
However, when I look in the "Logs & Monitor" in the SmartConsole it doesn't show/register any "Source User Name" as shown below:
It does occasionally show someone logging in on a client.
I've restarted the services before and it began working again after some time. Is this expected behaviour because of the "Association time-to-live" on the Identity Collectors or something like that?
And is there a way for me to make it work again now and not just having to wait?
I'm still a bit new to all this so please forgive me if I'm not all to clear in my explanations.
Thanks!
So, unfortunately it still doesn't work...
It registers when someone logs on to a client as seen below, however, not "regular" events:
But the IDC is both getting events from the AD and sending to the FW GW:
Any help would be appreciated!!
Better contact CP TAC and get this reviewed in RAS - a look into the configuration is necessary to resolve this...
Quickest path is probably to review with TAC.
Which Gateway & IDC version do you use out of interest?
It's R81 and the IDCs are build 81.040.0000.
It worked before I did the fw kill pdpd and fw kill pepd, so I'm quite certain it has something to do with that.
When I do the pdp status show it says there is no PEPs connected:
Is it perhaps because it has to rebuild the database after I restarted pdpd/pepd and the FW doesn't get old events/associations?
It could be, but better to get TAC involved to confirm, as the guys already said.
Best regards,
Andy
Which JHF take is applied to the Gateway, there are potentially relevant fixes here in addition to a newer IDC version
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 21 | |
| 20 | |
| 17 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY