> Source: [sk91463](https://support.checkpoint.com/results/sk/sk91463)

# sk91463 - Access role firewall rules are not enforced correctly

| Property | Value |
|----------|-------|
| Solution ID | sk91463 |
| Date Created | 2013-01-16 |
| Last Modified | 2016-12-25 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * Access role firewall rules are not enforced correctly
* PEP contains multiple values for the same user and IP or values that don't exist in PDP.
* A mismatch between the pep_client_db kernel table size and the pep_src_mapping_db kernel table size

## Cause

If there are two Identity Servers (PDP) that have AD Query enabled and that share identities with the same PEP, there will be two different sessions for a single IP address and the old session will overridden incorrectly. This is causing instability in the PEP tables and an undefined behavior.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
