> Source: [sk185098](https://support.checkpoint.com/results/sk/sk185098)

# sk185098 - Identity Awareness Gateway keeps a stale IP Address entry after IP address of Terminal Server changed

| Property | Value |
|----------|-------|
| Solution ID | sk185098 |
| Date Created | 2026-06-30 |
| Last Modified | 2026-07-05 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * A Policy Enforcement Point (PEP) Gateway does not match users to access roles based on information collected by Identity Agent for a Terminal Server (MUH). The affected users are assigned an IP address that was previously assigned to the Terminal Server.
* The Policy Enforcement Point (PEP) Gateway adds the new IP address entry, but the previous IP address entry remains in the `pep_id_range_db` kernel table. To view the kernel table, run this commandon the CLI of the PEP Gateway:`fw tab -t pep_id_range_db -u`.

## Cause

When the MUH client changes its IP address, the PEP Gateway processes the identity update and removes the old client IP mapping from the `pep_src_mapping_db` kernel table. However, the PEP does not remove the corresponding stale identity range entry from the `pep_id_range_db` kernel table.  

As a result, the PEP Gateway keeps an obsolete association for the old IP address. If that same IP address is later assigned to another user, the stale entry can interfere with correct access role matching.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
