> Source: [sk183274](https://support.checkpoint.com/results/sk/sk183274)

# sk183274 - Identity sessions on remote PEP gateway do not survive cluster failover or restart of Identity Sharing process

| Property | Value |
|----------|-------|
| Solution ID | sk183274 |
| Date Created | 2025-04-20 |
| Last Modified | 2025-04-28 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS) |

## Symptoms

- * In an Identity Sharing configuration with a remote Policy Enforcement Point (PEP) Identity Awareness Gateway, identity sessions do not survive cluster failover, Policy Decision Point (PDP) process restart, or PEP process restart.
* The version of the PDP Gateway is R81.10 (starting from Jumbo Hotfix Accumulator take 141), R81.20 (starting from Jumbo Hotfix Accumulator take 54), or R82.

## Cause

A Check Point administrator configured an alternate IP address for the PDP Gateway to use for communication with the Identity Server (for example: Identity Collector on a Windows server, Identity Agent for a Terminal Server). The PDP Gateway does not behave as expected.

## Solution

[Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.  
For faster resolution and verification, collect these files:

1. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Management Server involved in the case.
2. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Security Gateway / each Cluster Member involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).

#### Workaround

If you do not want to install a hotfix, you can resolve the issue by using the main address of the PDP Gateway for communication with the Identity Server. To do this, clear the value of the `ia_control_connections_ip` object in the database of the Management Server.

1. Close all SmartConsole windows (SmartDashboard, SmartView Tracker, etc.).

2. Connect with [Database Tool (GuiDBedit Tool)](http://supportcontent.checkpoint.com/solutions?id=sk13009) to the Security Management Server / Domain Management Server.

3. In the left upper pane, go to ***Table*** \> ***Network Objects*** \> ***network_objects***.

4. In the right upper pane, select the applicable Identity Awareness Gateway or Identity Server object.

5. Press CTRL+F (or go to ***Search*** menu \> ***Find*** ) - paste ***ia_control_connections_ip*** \> click ***Find Next***.

6. In the lower pane, right-click on the ***ia_control_connections_ip*** \> click ***Edit...*** \> clear the field \> click ***OK***.

7. Save the changes: go to the ***File*** menu \> click ***Save All***.

8. Close the Database Tool (GuiDBedit Tool).

9. Connect with SmartConsole to the Security Management Server / Domain Management Server.

10. If you have NAT rules for traffic between the Identity Server and the Identity Awareness Gateway, then in these NAT rules, you must change the translated destination IP address to the main IP address of the PDP Identity Awareness Gateway.

11. Install the Access Control policy on the Identity Awareness Gateway.

12. On all relevant PDP Identity Awareness Gateways, restart the PDPD process (to read the new configuration) with this command in the Expert mode:

    `fw kill pdpd`

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
