> Source: [sk113021](https://support.checkpoint.com/results/sk/sk113021)

# sk113021 - Identity Collector fails to connect / add / edit a Security Gateway

| Property | Value |
|----------|-------|
| Solution ID | sk113021 |
| Date Created | 2016-09-27 |
| Last Modified | 2025-06-24 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS) |

## Symptoms

- * When adding / editing the Security Gateway object, test connection fails.

* Security Gateway that has already successfully connected to the Identity Collector, disconnects after some time.

* "Identity collector can not connect to Security Gateway - refer to sk113021" is shown when using the "Test" button during the addition of a Gateway to the Identity Collector.

* Cannot use Identity Collector over Site-to-Site VPN on Locally Managed Quantum Spark appliance version R81.10.05 and higher.

## Cause

1. The Security Gateway's version does not support Identity Collector.
2. Identity Collector identity source is not configured correctly on the Security Gateway.
3. Security Gateway is not configured correctly on the Identity Collector.
4. Connection / routing issues between the Security Gateway and the Identity Collector.
5. Windows Firewall / Security Gateway policy blocks the connection between the Identity Collector and the Security Gateway.
6. Bad / Expired certificate on the Security Gateway. (see **Solution** section below, and [sk170112](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk170112)).
7. Security Gateway was configured with Cluster member IP instead of VIP.
8. "Wrong Shared Secret" occurs when connecting a Security Gateway to Identity Collector if the Authrized Clients object defined within the Gateway Properties on SmartConsole has the wrong IP.
9. Communication issue on the Windows Server hosting the IDC - proxy configuration or Windows Firewall not allowing connectivity between IDC and the configured Security Gateways.
10. Third party trusted CA blocking communication to the PDPD process.
11. A software limitation in VSX VSLS with 3 Members.
12. Quantum Spark Locally Managed appliances - Identity Collector connections through VPN encrypted interfaces are not allowed by default.
13. PDPD process is not listening on tcp port 5908 which is responsible for the communication with Identity Collector.

## Solution

### Wrong Shared Secret:

*

  ### For Security Gateway R80.10 and higher:

  Configure the correct shared secret as was configured on the client machine (on which the Identity Collector is installed):

  ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk113021/R80_10_Authorized_Clients.png)

### Configuration in Security Gateway object:

*

  ### For Security Gateway R80.10 and higher:

  1. Enable the Identity Awareness blade.

  2. Enable the Identity Collector as one of the identity sources.

  3. Configure the shared secret in the Identity Collector settings , (it should match to the one which was configured on the client machine - on which the Identity Collector is installed).

  4. In case the Identity Collector will connect to the Security Gateway through non-internal interface, change the Accessibility configuration.

  5. Install the policy.

  [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk113021/R80_10_Accessibility.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk113021/R80_10_Accessibility.png "Click the image to see it in full size in a new tab/window")
* **NOTE**: in case the customer configuration is "Through Internal Interfaces" make sure that the necessary interfaces are included, the identities might not be accepted if we do not include the relevant interfaces, bellow attached a screenshot of problematic "Through Internal Interface" configuration.

  ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk113021/through internal interfaces202302231310481.png)

### Configuration on Identity Collector:

1. For Security Gateway R80.10 and higher, clear the box "***Pre R80.X Gateway***".

   [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk113021/R80_10_GW.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk113021/R80_10_GW.png "Click the image to see it in full size in a new tab/window")
2. Go to ***Edit Security Gateway*** and click on ***Test*** button.

3. If the certificate needs to be approved or updated, do it.

4. Check that the shared secret is the same shared secret as configured in the Security Gateway object (in SmartDashboard / SmartConsole).

5. Click on OK to save the configuration changes.

6. In Cluster environment - make sure the configured IP is the Virtual IP (VIP) and not the member IP.

7. If none of the above worked, try to renew the certificate as explained in the next section.

*** ** * ** ***

*

  ### For Security Gateway R77.30 and lower:

  Configure the correct shared secret in the SmartDashboard.

  [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk113021/R7X_pre_shared_secret.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk113021/R7X_pre_shared_secret.png "Click the image to see it in full size in a new tab/window")

### Timeout:

1. Check that routing is configured correctly and works between the Identity Collector Client and Security Gateway.

2. Check that the connection between the Identity Collector and the Security Gateway over HTTPS protocol (TCP port 443) is not blocked:

   * On the client machine (on which the Identity Collector is installed):

     Check that the Windows Firewall does not block this connection
   * For Security Gateway R77.30 and lower:

     Check that security policy does not block this connection
   * On any FireWall between the Identity Collector and the Security Gateway (if installed):

     Check that the security policy on that FireWall does not block this connection
3. If none of these steps resolve the issue, then proceed to the next section.

### Configuration in Security Gateway object:

*

  ### For Security Gateway R77.30 and lower:

  1. Check that this version supports Identity Collector:

     **`[Expert@HostName:0]# cpvinfo $FWDIR/lib/libpdplib.so | grep -E "Minor|Build"`**

     Output should show:
     * Either:

       ```
       Minor = gollum_hf_base_016
       Build = 990016016 (or above)
       ```

     * Or:

       ```
       Minor = giraffe_v2
       Build = 990016019 (or above)
       ```

  2. Enable the Identity Awareness blade.

  3. Enable Terminal Servers as one of the identity sources.

  4. In the Settings of Terminal Servers, configure the shared secret (or generate it automatically).

  5. In case the Identity Collector will connect to the Security Gateway through a non-internal interface, change the Accessibility configuration.

  6. Install the policy.

  [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk113021/R7X_Accessibility.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk113021/R7X_Accessibility.png "Click the image to see it in full size in a new tab/window")

### Configuration on Identity Collector:

1. For Security Gateway R77.30 and lower, check the box "***Pre R80.X Gateway***".

   [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk113021/cfgGW1609282028.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk113021/cfgGW1609282028.png "Click the image to see it in full size in a new tab/window")
2. Go to ***Edit Security Gateway*** and click on ***Test*** button.

3. If the certificate needs to be approved or updated, do it.

4. Check that the shared secret is the same shared secret as configured in the Security Gateway object (in SmartDashboard / SmartConsole).

5. Click on OK to save the configuration changes.

6. If none of the above worked, try to renew the certificate as explained in the next section.

### Certificate Issue: {#Gateway_certificate}

1. Sometimes the issue is the Security Gateway certificate, which is corrupted or outdated. Follow [sk105723 - Terminal Servers Identity Agent (MUH Agent) shows its status as "Disconnected"](https://support.checkpoint.com/results/sk/sk105723).
2. The Certificate was expired on the Identity Awareness Security Gateway. Please check [sk180644](https://support.checkpoint.com/results/sk/sk180644) for more details.
3. Identity Awareness Gateway has a third-party certificate installed. Platform Portal certificate on SmartConsole shows an error: "*The portal certificate expired on* ...."  

   ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk113021/IDA_cert_iisu1805141343.png)

<br />

Debug collected on the Windows client having installed Identity Collector based on [Identity Awareness Clients Administration Guide](https://sc1.checkpoint.com/documents/Identity_Awareness_Clients_Admin_Guide/Default.htm) \> Identity Collector \> Identity Collector - Debug shows:

`[ ...]@Host[DATE TIME] [WinHttpCCC (NAC::IS::TD::Events)] UTILS::WinHttpCCC::run: WinHttpSendRequest failed with 2f8f`  
`[ ...]@Host[DATE TIME] [WinHttpCCC (NAC::IS::TD::Events)] UTILS::WinHttpCCC::requestFinished: Request finished: retries left (including this one): 0``[ ...]@Host[DATE TIME] [WinHttpCCC (NAC::IS::TD::Events)] UTILS::WinHttpCCC::requestFinished: No retries left, notify failed request``[ ...]@Host[DATE TIME] [WinHttpCCC (NAC::IS::TD::Events)] UTILS::WinHttpCCC::run: Sending message of topic IDCLogEvent, remaining retries 1`  
`[ ...]@Host[DATE TIME] [WinHttpCCC (NAC::IS::TD::Important)] UTILS::WinHttpCCC::dataArrivedCB: Notifying failed request`  
`[ ...]@Host[DATE TIME] [PDPChannel (NAC::IS::TD::Events)] NAC::IDCOLLECTOR::PDPChannel::Notify: retrieved notification for pdp 10.160.130.2, request_id 2: CCC return code 399`  
`[ ...]@Host[DATE TIME] [PDPChannel (NAC::IS::TD::Events)] NAC::IDCOLLECTOR::PDPChannel::Notify: retrieved notification for pdp 10.160.130.2, request_id 2: NAC return code 1`  
`[ ...]@Host[DATE TIME] [PDPChannel (NAC::IS::TD::Events)] NAC::IDCOLLECTOR::PDPChannel::setErrCodes: setErrCodes - setting error codes: ccc err 399, nac err 1`

<br />

Follow these steps to resolve the problem:

1. Obtain new Root CA from the same third party vendor, where the Identity Awareness Gateway obtained its certificate.

   On SmartDashboard, for problematic Gateway where Identity Collector configured:
   1. Replace the old certificate from the Trusted Root Certification Authorities store.

   2. Add the new certificate obtained in Step 1 to the Trusted Root Certification Authorities store.

2. Install policy to the Identity Awereness Security Gateway.

**Communication issue**

In case the Identity Collector *config.idc* file shows similiar details for the defined Security Gateway:

`name (test_IA_gateway) :address (192.168.1.1) :url ("/_IA_MU_Agent/ccc") :fingerprint () :port (443) :enabled (1) :trusted (False) :bc (True) :cn () :filter () :comment () `**No associated fingerprint and trusted is determined as "false"**`.`

And ia_ag.log debug output from the Identity Collector shows:

`[WinHttpCCC (NAC::IS::TD::Events)] UTILS::WinHttpCCC::run: Sending message of topic IDCEvent, remaining retries 1`  
` [WinHttpCCC (NAC::IS::TD::Events)] UTILS::WinHttpCCC::run: Got 0 bytes `  
`[WinHttpCCC (NAC::IS::TD::Events)] UTILS::WinHttpCCC::run: No response `  
`[WinHttpCCC (NAC::IS::TD::Events)] UTILS::WinHttpCCC::requestFinished: Request finished: retries left (including this one): 0 `  
`[WinHttpCCC (NAC::IS::TD::Events)] UTILS::WinHttpCCC::requestFinished: No retries left, notify failed request `  
`[Event (NAC::IS::TD::Events)] UTILS::Event::wait: Wait`  
` [WinHttpCCC (NAC::IS::TD::Important)] UTILS::WinHttpCCC::dataArrivedCB: Notifying failed request (no return request) `  
`[PDPChannel (NAC::IS::TD::Events)] NAC::IDCOLLECTOR::PDPChannel::Notify: retrieved notification for pdp 192.168.1.1, request_id 1: CCC return code 399`  
` [PDPChannel (NAC::IS::TD::Events)] NAC::IDCOLLECTOR::PDPChannel::Notify: retrieved notification for pdp 192.168.1.1, request_id 1: NAC return code 1 `  
`[PDPChannel (NAC::IS::TD::Events)] NAC::IDCOLLECTOR::PDPChannel::setErrCodes: setErrCodes - setting error codes: ccc err 399, nac err 1 `  
`[PDPChannel (TD::Events)] NAC::IDCOLLECTOR::PDPChannel::eraseFromRequestNotificationMap: deleting request 1 connection notification Output notes a `**communication issue between the Identity Collector and the Security Gateway**`.`

Resolve the communication issue on the Windows server.

**Third party trusted CA blocking communication to the PDPD process.**

Within SmartConsole from the Security Management server that manages the firewall in question, navigate to the side tabs under "Servers -\> Trusted CA".

* If there are other certificates listed other then "internal_ca", try to view them by double-clicking it and navigating to the "Local Security Management Server" tab.
* If you can not "view" the certificate, it needs to be deleted and re-imported or permanently deleted once you have verified its not in use.

These third party Trusted CA's are blocking the communication from the IDC to the PDPD process.

<br />

<br />

**Issue with VSX VSLS with 3 Members**

Additional symptoms:

* VSX VSLS with 3 Members Fails to Connect to Identity Collector.
* On the Gateway side you see: "Peer closed the connection". On the Identity Collector: "general transport error 399".
* Connectivity between Security Gateway and Identity Collector was working previously.
* Security Gateway and Identity Collector are returning "Error: refer to sk113021"

Solution:

Issue is related to PMTR-53549.

This problem was fixed. The fix is included in:

* [Check Point R81](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk166715)

Check Point recommends to always upgrade to the most recent version   
([upgrade Security Gateway](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=435) / [upgrade Security Management Server](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=184) / [upgrade Multi-Domain Security Management](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=166)).

If you choose not to upgrade, Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.  

**Identity collector cannot connect to MDPS gateway**Additional symptoms:

* The Security Gateway isolates the Management and Data networks with Management Data Plane Separation (MDPS).
* The certificate used for the commnications(by default it is *defaultcert* - in the VPN blade) is valid and does not have a term longer than one year.
* Output of zdebug + crypt from the PDP gateway shows this error:

  ```
  @;777454710;[vs_0];[tid_1];[fw4_1];client_conn �: dir 0, IDC IP address:58630 -> PDP IP address:443 IPP 6;

  @;777454710;[vs_0];[tid_1];[fw4_1];rulenum � � �: 12;

  @;777454710;[vs_0];[tid_1];[fw4_1];http redirect: 0;

  @;777454710;[vs_0];[tid_1];[fw4_1];brother_conn : 0x7fc40d219060;

  @;777454710;[vs_0];[tid_1];[fw4_1];server_conn �:�

  �PDP IP address:5908 IPP 6>;

  ...

  vm_mux_cpas_3rd_party_event_handler: received CPAS_CONN_RESET on CPAS_SERVER_SIDE;

  ```

Cause:  
Identity Collector was configured to the mplane IP address of the Security Gateway.  
In an MDPS configuration, the Management and Data networks are seperated. As a result, the PDP cannot establish a connection with Identity Collector.  

**PDPD is not listening on tcp port 5908.**   
PDPD listens on port 5908 to handle the connection from the Identity Collector, check the port with this command to see that if the port is listened by PDPD correctly or not. If not, try to restart the PDPD process and verify it again.  

`[Expert@HOSTNAME:0]# netstat -nlp | grep pdpd`  
`tcp 0 0 127.0.0.1:3310 0.0.0.0:* LISTEN 15319/pdpd `  
`tcp 0 0 127.0.0.1:8094 0.0.0.0:* LISTEN 15319/pdpd `  
`tcp 0 0 127.0.0.1:8099 0.0.0.0:* LISTEN 15319/pdpd `  
**tcp 0 0 :::5908 :::* LISTEN 15319/pdpd**` `  
`tcp 0 0 :::28581 :::* LISTEN 15319/pdpd `  
`tcp 0 0 :::17000 :::* LISTEN 15319/pdpd `   

Use the following command to restart PDPD:  

`[Expert@HOSTNAME:0]# fw kill pdpd`  

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
