pdp

Description

These commands control and monitor the pdpd process.

Syntax

pdp <command> [<parameter> [<option>]]

Commands

Parameter

Description

No Parameters

Shows available options for this command and exits.

ad <parameter> <option>

For the AD QueryClosed Check Point clientless identity acquisition tool. It is based on Active Directory integration and it is completely transparent to the user. The technology is based on querying the Active Directory Security Event Logs and extracting the user and computer mapping to the network address from them. It is based on Windows Management Instrumentation (WMI), a standard Microsoft protocol. The Check Point Security Gateway communicates directly with the Active Directory domain controllers and does not require a separate server. No installation is necessary on the clients, or on the Active Directory server., adds (or removes) an identity to the Identity AwarenessClosed Check Point Software Blade on a Security Gateway that enforces network access and audits data based on network location, the identity of the user, and the identity of the computer. Acronym: IDA. database on the Security GatewayClosed Dedicated Check Point server that runs Check Point software to inspect traffic and enforce Security Policies for connected network resources..

See pdp ad.

auth <parameter> <option>

Shows authentication or authorization options.

See pdp auth.

broker <parameter> <option>

Controls the PDPClosed Check Point Identity Awareness Security Gateway that acts as Policy Decision Point: acquires identities from identity sources; shares identities with other gateways. Identity BrokerClosed Identity Sharing mechanism between Identity Servers (PDP): (1) Communication channel between PDPs based on Web-API (2) Identity Sharing capabilities between PDPs - ability to add, remove, and update the identity session..

See pdp broker.

conciliation <parameter> <option>

Controls the session conciliation mechanism.

See pdp conciliation.

connections <parameter>

Shows the PDP connections with the PEPClosed Check Point Identity Awareness Security Gateway that acts as Policy Enforcement Point: receives identities via identity sharing; redirects users to Captive Portal. gateways, Terminal Servers, and Identity Collectors.

See pdp connections.

control <parameter> <option>

Controls the PDP parameters.

See pdp control.

debug <parameter> <option>

Controls the PDP debug.

See pdp debug.

idc <parameter> <option>

Operations related to Identity CollectorClosed Check Point dedicated client agent installed on Windows Servers in your network. Identity Collector collects information about identities and their associated IP addresses, and sends it to the Check Point Security Gateways for identity enforcement. You can download the Identity Collector package from Support Center..

See pdp idc.

idp <parameter> <option>

Operations related to SAML-based authentication.

See pdp idp.

monitor <parameter> <option>

Monitors the status of connected PDP sessions.

See pdp monitor.

muh <parameter> <option>

Shows Multi-User Hosts (MUHs).

See pdp muh.

nested_groups <parameter>

Shows LDAP Nested groups configuration.

See pdp nested_groups.

network <parameter>

Shows information about network related features.

See pdp network.

radius <parameter> <option>

Shows and configures the RADIUS accounting options.

See pdp radius.

roles <parameter> <option>

Shows the user role information.

See pdp roles.

status <parameter>

Shows PDP status information, such as start time or configuration time.

See pdp status.

tasks_manager <parameter>

Shows the status of the PDP tasks.

See pdp tasks_manager.

timers <parameter>

Shows PDP timers information for each session.

See pdp timers.

topology_map

Shows topology of all PDP and PEP addresses.

See pdp topology_map.

tracker <parameter>

Adds the TRACKER topic to the PDP logs.

See pdp tracker.

update <parameter>

Recalculates users and computers group membership.

See pdp update.

vpn <parameter>

Shows connected VPN gateways that send identity data from VPN Remote Access Clients.

See pdp vpn.