> Source: [sk166218](https://support.checkpoint.com/results/sk/sk166218)

# sk166218 - Users with Access Roles are unable to match against Rules with those Access Roles

| Property | Value |
|----------|-------|
| Solution ID | sk166218 |
| Date Created | 2020-04-08 |
| Last Modified | 2021-02-22 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * Users with Access Roles do not match against rules.
* Affected users have entries in both PDP and PEP tables. This can be checked using:  
  `# pdp m ip [IP] `  
  `# pep sh u q cid [IP] `  

  The identity sources in use are:  
  * Identity Collector
  * Captive Portal

## Cause

Issue occurs in a cluster environment and (potentially) after a fail-over. The identity collector is configured with both physical cluster IPs as two separate gateway objects.  
The Identity Collector (IDC) is using the physical IP addresses of both cluster members instead of the VIP of the cluster (2 objects for the cluster instead of one).

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
