> Source: [sk182613](https://support.checkpoint.com/results/sk/sk182613)

# sk182613 - Identity sync latency between PEP and PDP daemons

| Property | Value |
|----------|-------|
| Solution ID | sk182613 |
| Date Created | 2024-08-29 |
| Last Modified | 2025-02-23 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82, R81.20, R81.10 (EOS) |

## Symptoms

- * The "pdp task stat" command shows the PDP and PEP identities sync is progressing slowly.
* Some AD users fail to match the Access Role.
* High CPU utilization is not seen.
* After enabling the pdp debug by executing "pdp debug set all all", pdp debug fails. Also, when running "pdp debug off" to disable the pdp debug, it fails with the error "daemon did not respond or not running".
* The CP commands (such as, cpview, cphaprob, asg, pdp etc.) stuck without outputs after the pdp debug.
* Rebooting the affected security gateway doesn't remediate the issue.
* Restarting the pdpd daemon by executing "kill -9 \`pidof pdpd\`" or "fw kill pdpd" can let the CP commands work. However, PDP and PEP identities sync still running slowly.
* There are more than 200 Access Role objects.
* The "$FWDIR/log/pepd.elg.x" log file shows the below example snippet:   
  > `fwasync_conn_get: get max buffer size (268435456) .`  
  > `
  > fwasync_conn_get: requested length too big (497573567). Closing the connection. `

## Solution

This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 10
* [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 96
* [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 173

If you choose not to upgrade, Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/.contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).  

**Quick remediation:**Reduce the Role Access object amount to less than 100.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
