> Source: [sk183098](https://support.checkpoint.com/results/sk/sk183098)

# sk183098 - Cisco ISE users are not identified with the Identity tags configured for them

| Property | Value |
|----------|-------|
| Solution ID | sk183098 |
| Date Created | 2025-02-02 |
| Last Modified | 2025-02-04 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82, R81.20, R81.10 (EOS) |

## Symptoms

- * Cisco Identity Services Engine (ISE) users cannot access resources located behind an Identity Awareeness Gateway.
* The Identity Awareness Gateway does not match the Cisco ISE users to access control rules defined with identity tags.
* On the Identity Awareness Policy Decision Point (PDP) Security Gateway, the parameter `pdp idc groups_consolidation status` is disabled.

## Cause

When the `# pdp idc groups_consolidation status` parameter is disabled, the expected behavior is for the Security Gateway to create the $*FWDIR/conf/pdp_overriding_attrs.C* file and **not** to fetch Active Directory (AD) groups for the Cisco ISE Users. However, the Security Gateway does not create the file and it does try to fetch the AD groups. The AD lookup fails, and as a result the Security Gateway does not match the Cisco ISE users to rules.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
