> Source: [sk180712](https://support.checkpoint.com/results/sk/sk180712)

# sk180712 - Azure Data Center Tag Intermittently Enforced

| Property | Value |
|----------|-------|
| Solution ID | sk180712 |
| Date Created | 2023-03-10 |
| Last Modified | 2023-03-16 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- You add to the Security Policy a drop rule with Azure data center object and it starts to drop traffic. After some time traffic stops to match that rule, and match another rule or the cleanup rule.

## Cause

The Azure Data Center object IP addresses overlap with servers in other Identity Sources.  
This overlapping causes the disassociation of the IP addresses from the Data Center Object, or Access Roles with such Machines, and improper Security Policy enforcement.

## Solution

Create an exception for the IP of the data center object in the other identity sources.

1. Create exception in ADquery:

   Open the Security Gateway object in SmartConsole \> **Identity awareness** \> **ADquery settings** \> **Advanced**\> add IP of the data center object in excluded networks.
2. Create exception in Identity Collector:

   Open Identity Collector object \> **Filters** \> add IP of the data center object in **Exclude** tab in Network Filter tab.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
