sk183268 - Users from Terminal Server Identity Agent (MUH Agent) servers do not match rules with access roles

Users from Terminal Server Identity Agent (MUH Agent) servers do not match rules with access roles

Product: Identity Awareness
Version: R81.10 (EOS), R81.20, R82
OS: Gaia
Last Modified: 2026-02-17

Symptoms

Cause

There was an issue with handling the kernel table entries that associate a user's session id to their port/id range when the relevant agent was configured with dual-stacked IP addresses.

Duplicate entries could occur due to a failure to remove expired entries from this table (pep_id_port_range / pep_port_range_db).

Despite the MUH agent correctly transmitting user identity information, a non-existent user session could be returned from the kernel table query in this scenario leading to the user not being recognized.

Solution

This problem was fixed. The fix is included in:

If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.

Hotfix installation instructions: Refer to sk168597 - How to install a Hotfix.

In case of a cluster, after installing the HF (Also can be applied as a workaround before installing the HF), you also need to clear the Identity Awareness Kernel tables on all members at the same time.

NOTE: This should be performed after working hours or maintenance as it will clear all Identity awareness information. The information will be learned again when users connect to Windows again, or when the agents reconnect to the GW.

In case of a VSX, run the command from the relevant VS ID context (vsenv ).

# cat $FWDIR/lib/nac_tables.def | grep dynamic | cut -d ' ' -f1 | grep -v idp | awk '{ print ("-t "$0"")}' ORS=" " | awk '{print "fw tab "$0" -x -y"}' | bash ; fw kill pdpd ; fw kill pepd

In case of a Maestro Security Group, please run the following command instead:

# cat $FWDIR/lib/nac_tables.def | grep dynamic | cut -d ' ' -f1 | grep -v idp | awk '{ print ("-t "$0"")}' ORS=" " | awk '{print "g_fw tab "$0" -x -y"}' | bash ; g_fw kill pdpd ; g_fw kill pepd

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version, and Symptoms. It may not work in other scenarios.

Article Properties

Access Level: General
Status: Approved by TAC
Date Created: 2025-03-19
Last Modified: 2026-02-17