> Source: [sk63264](https://support.checkpoint.com/results/sk/sk63264)

# sk63264 - In a Cluster environment, Identity propagation does not occur between an Identity Server (PDP) and Identity Gateway (PEP)

| Property | Value |
|----------|-------|
| Solution ID | sk63264 |
| Date Created | 2011-06-19 |
| Last Modified | 2025-01-16 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R81 (EOS) |

## Symptoms

- * If a cluster was configured as Identity Gateway (PEP), then:

  * On the Identity Server (PDP), the "`pdp connections pep`" command displays the incoming connections from the physical IP addresses of the cluster members (configured as PEP), rather than the Cluster Virtual IP address.

  * The cluster (configured as PEP) is not updated about identities by the Identity Server (PDP).

* If a cluster was configured as Identity Server (PDP), then:

  * On the Identity Gateway (PEP), the "`pep show pdp all`" command displays the incoming connections from the physical IP addresses of the cluster members (configured as PDP), rather than the Cluster Virtual IP address.

  * The cluster (configured as PDP) does not update the Identity Gateway (PEP) about identities.

## Cause

In a Cluster environment, the connections from PEP to PDP (over TCP port 28581) and from PDP to PEP (over TCP port 15105) are expected to be initiated from the Cluster's Virtual IP addresses, rather than from the physical IP addresses of cluster members.

## Solution

Follow the steps below.

If a cluster was configured as an Identity Gateway (PEP)
--------------------------------------------------------

> * **The cluster that is configured as PEP is *ClusterXL*:**
>
>   1. Make sure that [sk31832](http://supportcontent.checkpoint.com/solutions?id=sk31832) is ***not*** applied on the cluster members for TCP port 28581.
>
>      If such a configuration exists, remove it.
>   2. If the issue persists, add the following NAT rule ***above*** the existing NAT rules to hide the PEP connections originated by the PEP cluster members behind the PEP Cluster Virtual IP address:
>
>      In R8x SmartConsole:
>
>      |-----|---------------------------|-----------------------|-------------------|-------------------|------------------------|---------------------|--------------------|
>      | No. | Original Source           | Original Destination  | Original Services | Translated Source | Translated Destination | Translated Services | Install On         |
>      | 1   | PEP Member_A PEP Member_B | PDP Gateway / Cluster | TCP 28581         | PEP Cluster VIP   | `= Original`           | `= Original`        | PEP Cluster object |
>
>      In R7x SmartDashboard:
>
>      |-----|---------------------------|-----------------------|-----------|-----------------|--------------|--------------|--------------------|
>      | No. | Original Packet                                             ||| Translated Packet                           ||| Install On         |
>      | No. | Source                    | Destination           | Service   | Source          | Destination  | Service      | Install On         |
>      | 1   | PEP Member_A PEP Member_B | PDP Gateway / Cluster | TCP 28581 | PEP Cluster VIP | `= Original` | `= Original` | PEP Cluster object |
>
> * **The cluster that is configured as PEP is a *3rd party* cluster:**
>
>   1. In SmartDashboard, open the 3rd party cluster object.
>
>   2. From the left tree, click **3rd Party Configuration**.
>
>   3. Select **Hide Cluster Members' outgoing traffic behind the Cluster's IP address**.
>
>   4. Click **OK**.
>
>   5. Install the Network Security policy on this cluster object.
>
>   *Example* :  
>   [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk63264/3rd_party.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk63264/3rd_party.png "Click the image to see it in full size in a new tab/window")

If a cluster was configured as an Identity Server (PDP)
-------------------------------------------------------

> * **The cluster that is configured as PDP is *ClusterXL*:**
>
>   1. Make sure that [sk31832](http://supportcontent.checkpoint.com/solutions?id=sk31832) is ***not*** applied on the cluster members for TCP port 15105.
>
>      If such a configuration exists, remove it.
>   2. If the issue persists, add the following NAT rule ***above*** the existing NAT rules to hide the PDP connections originated by the PDP cluster members behind the PDP Cluster Virtual IP address:
>
>      In R80.x SmartConsole:
>
>      |-----|---------------------------|-----------------------|-------------------|-------------------|------------------------|---------------------|--------------------|
>      | No. | Original Source           | Original Destination  | Original Services | Translated Source | Translated Destination | Translated Services | Install On         |
>      | 1   | PDP Member_A PDP Member_B | PEP Gateway / Cluster | TCP 15105         | PDP Cluster VIP   | `= Original`           | `= Original`        | PDP Cluster object |
>
>      In R7x SmartDashboard:
>
>      |-----|---------------------------|-----------------------|-----------|-----------------|--------------|--------------|--------------------|
>      | No. | Original Packet                                             ||| Translated Packet                           ||| Install On         |
>      | No. | Source                    | Destination           | Service   | Source          | Destination  | Service      | Install On         |
>      | 1   | PDP Member_A PDP Member_B | PEP Gateway / Cluster | TCP 15105 | PDP Cluster VIP | `= Original` | `= Original` | PDP Cluster object |
>
> * **The cluster that is configured as PDP is a *3rd party* cluster:**
>
>   1. In SmartDashboard, open the 3rd party cluster object.
>
>   2. From the left tree, click **3rd Party Configuration**.
>
>   3. Select **Hide Cluster Members' outgoing traffic behind the Cluster's IP address**.
>
>   4. Click OK.
>
>   5. Install the Network Security policy on this cluster object.
>
>   *Example* :  
>   [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk63264/3rd_party.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk63264/3rd_party.png "Click the image to see it in full size in a new tab/window")

### Notes

* If an existing Identity Awareness connection is established with other Security Gateways, you must restart the PDP services on the affected Security Gateways with the "**fw kill pdpd**" command.

**This procedure includes inevitable downtime.**   

### Related Documentation

* Identity Awareness Administration Guide (see the [Product Page](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=documents&product=436))
* [sk60701 - Alternate IP Address for Identity Awareness communication channel](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk60701)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
