<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Logging issues in R81.10 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logging-issues-in-R81-10/m-p/158747#M27708</link>
    <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1702"&gt;@JozkoMrkvicka&lt;/a&gt;&amp;nbsp;, but that was not the issue, it was the first thing I checked actually.&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;was 100% correct as usual...no offense to anyone else, but he is after all CP master/guru/legend/expert...whatever you want to call it :). I enabled to log implied rules and sure enough, it started to show logs to google dns right away. Funny enough, that option was NOT enabled in R81 and logs were showing actual rule number.&lt;/P&gt;</description>
    <pubDate>Tue, 04 Oct 2022 14:56:57 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2022-10-04T14:56:57Z</dc:date>
    <item>
      <title>Logging issues in R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logging-issues-in-R81-10/m-p/158685#M27682</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;
&lt;P&gt;I hope someone might be able to shed some light about this. So, while back, I set up a lab with base R81, mgmt server + 2 single gateways and all works fine, no issues. I upgraded all to R81.10 and still going strong : -).&lt;/P&gt;
&lt;P&gt;Now, the other week, to demonstrate R81.10 from scratch to a customer, I built brand new R81.10 (mgmt server + HA cluster) and all seems fine, except I see some odd issues with logging. For example, if I refresh the logs in dashboard, looks okay, but...say if I ping 8.8.8.8 from either cluster member, I can never see any logs, which is not the case in my other lab (works fine). I followed support sk's for this, rebooted many times, did fw logswitch, literally all the steps and still no luck.&lt;/P&gt;
&lt;P&gt;I am totally at a loss why this would be happening, makes no logical sense to me.&lt;/P&gt;
&lt;P&gt;If anyone can provide some suggestions, I would appreciate it. Anyway, its nothing urgent, since its a lab, but its really puzzling to me why its not working.&lt;/P&gt;
&lt;P&gt;tx as always!!&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2022 14:01:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logging-issues-in-R81-10/m-p/158685#M27682</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-10-03T14:01:52Z</dc:date>
    </item>
    <item>
      <title>Re: Logging issues in R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logging-issues-in-R81-10/m-p/158698#M27687</link>
      <description>&lt;P&gt;Outbound traffic from the gateway is almost always handled through an implied rule that doesn't log, last I checked...&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2022 16:23:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logging-issues-in-R81-10/m-p/158698#M27687</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-03T16:23:51Z</dc:date>
    </item>
    <item>
      <title>Re: Logging issues in R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logging-issues-in-R81-10/m-p/158700#M27689</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;. That makes sense, but then how come I see the log via right policy in my other lab?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2022 16:28:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logging-issues-in-R81-10/m-p/158700#M27689</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-10-03T16:28:30Z</dc:date>
    </item>
    <item>
      <title>Re: Logging issues in R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logging-issues-in-R81-10/m-p/158705#M27690</link>
      <description>&lt;P&gt;Not sure, maybe the implied rules were changed?&lt;BR /&gt;Or perhaps there is a code changes that impacts this behavior somehow?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2022 16:41:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logging-issues-in-R81-10/m-p/158705#M27690</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-03T16:41:14Z</dc:date>
    </item>
    <item>
      <title>Re: Logging issues in R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logging-issues-in-R81-10/m-p/158707#M27691</link>
      <description>&lt;P&gt;I hope you enable log in the rule that allows the traffic, my thought !&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2022 17:09:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logging-issues-in-R81-10/m-p/158707#M27691</guid>
      <dc:creator>Abi</dc:creator>
      <dc:date>2022-10-03T17:09:15Z</dc:date>
    </item>
    <item>
      <title>Re: Logging issues in R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logging-issues-in-R81-10/m-p/158710#M27693</link>
      <description>&lt;P&gt;I know even after 15 years it would be easy to forget, but it was enabled ;). I think&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;is correct.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2022 17:30:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logging-issues-in-R81-10/m-p/158710#M27693</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-10-03T17:30:51Z</dc:date>
    </item>
    <item>
      <title>Re: Logging issues in R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logging-issues-in-R81-10/m-p/158711#M27694</link>
      <description>&lt;P&gt;Definitely no change in implied rules.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2022 17:31:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logging-issues-in-R81-10/m-p/158711#M27694</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-10-03T17:31:26Z</dc:date>
    </item>
    <item>
      <title>Re: Logging issues in R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logging-issues-in-R81-10/m-p/158730#M27701</link>
      <description>&lt;P&gt;Make sure the date and time are correctly configured on gateway and management (log server). You might see logs with huge delays while the date is not correct on one of devices. Best to use NTP to avoid issue.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2022 05:52:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logging-issues-in-R81-10/m-p/158730#M27701</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2022-10-04T05:52:47Z</dc:date>
    </item>
    <item>
      <title>Re: Logging issues in R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logging-issues-in-R81-10/m-p/158747#M27708</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1702"&gt;@JozkoMrkvicka&lt;/a&gt;&amp;nbsp;, but that was not the issue, it was the first thing I checked actually.&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;was 100% correct as usual...no offense to anyone else, but he is after all CP master/guru/legend/expert...whatever you want to call it :). I enabled to log implied rules and sure enough, it started to show logs to google dns right away. Funny enough, that option was NOT enabled in R81 and logs were showing actual rule number.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2022 14:56:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logging-issues-in-R81-10/m-p/158747#M27708</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-10-04T14:56:57Z</dc:date>
    </item>
  </channel>
</rss>

