> Source: [sk180659](https://support.checkpoint.com/results/sk/sk180659)

# sk180659 - User identities are erased on the PDP Identity Awareness Gateway after subsequent policy installations

| Property | Value |
|----------|-------|
| Solution ID | sk180659 |
| Date Created | 2023-02-23 |
| Last Modified | 2023-04-13 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * End-users on a network protected by an Identity Awareness Gateway complain about network connectivity.

* This issue started after subsequent policy installations.

* Logs in SmartConsole show that the end-users are not authenticated properly from time to time.

* Output of the "`pdp task stat`" command on the Identity Awareness Gateway shows:

  *Revoke all sessions received from unknown publishers*
* Debug of the PDP daemon on the Identity Awareness Gateway shows in the *$FWDIR/log/pdpd.elg* file:

  *\[xxxx\]@Hostname\[Date Time\] \[TRACKER\]: #number -\> INTERNAL -\> TASK_STARTED -\> Starting task XXX: Revoke all identities received from publisher: (xx.xx.xx.xx)*
* This environment is configured to use the Identity Broker feature on Identity Awareness Gateways.

## Cause

During subsequent policy installations (with an interval of at least 11 minutes between them), the Identity Awareness Gateway configured as an Identity Broker Subscriber revoked all Identities it learned from the Identity Awareness Gateway configured as its Identity Broker Publisher.

## Solution

This problem was fixed. The fix is included starting from:

* [Check Point R81.20](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=skXXX)
* [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 95
* [Jumbo Hotfix Accumulator for R81](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm) starting from Take 82
* [Jumbo Hotfix Accumulator for R80.40](https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.40/Default.htm) starting from Take 196

If you choose not to upgrade, [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for your version.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.  
For faster resolution and verification, collect [CPinfo](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92739) files from the Management Server and Security Gateways / Cluster Members involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
