<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Some traffic not showing up in the logs in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-traffic-not-showing-up-in-the-logs/m-p/165233#M29620</link>
    <description>&lt;P&gt;One known occurrence would be if the same traffic was being seen by the gateway twice unexpectedly (&lt;SPAN&gt;sk172204)&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;but that's not specific to VoIP rather a topology or routing issue.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 14 Dec 2022 23:58:14 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2022-12-14T23:58:14Z</dc:date>
    <item>
      <title>Some traffic not showing up in the logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-traffic-not-showing-up-in-the-logs/m-p/165226#M29615</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We have a Security Gateway with version R81.10 and SecureXL enabled on the "Secure" Interfaces (DMZ interfaces).&lt;/P&gt;&lt;P&gt;We are troubleshooting SIP traffic issues with traffic going through one of the DMZ interfaces.&lt;/P&gt;&lt;P&gt;When we generate traffic, most specifically UDP traffic, some of the traffic, but not all of the traffic appears in the logs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;I am wondering if this is due to the SecureXL being enabled therefore not all allowed traffic is inspected (logged).&lt;/P&gt;&lt;P&gt;Or could there be a problem somewhere else that causes not all traffic to be visible in the logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and Kind regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 22:47:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-traffic-not-showing-up-in-the-logs/m-p/165226#M29615</guid>
      <dc:creator>P_M</dc:creator>
      <dc:date>2022-12-14T22:47:03Z</dc:date>
    </item>
    <item>
      <title>Re: Some traffic not showing up in the logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-traffic-not-showing-up-in-the-logs/m-p/165230#M29618</link>
      <description>&lt;P&gt;You could disable sxl to make sure, but that should not cause traffic not being visible in the logs, at least I had never seen that.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 23:02:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-traffic-not-showing-up-in-the-logs/m-p/165230#M29618</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-14T23:02:37Z</dc:date>
    </item>
    <item>
      <title>Re: Some traffic not showing up in the logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-traffic-not-showing-up-in-the-logs/m-p/165231#M29619</link>
      <description>&lt;P&gt;Just because something is accelerated with SecureXL doesn't mean it won't get logged.&lt;BR /&gt;It could also be logged differently than you expect as well.&lt;/P&gt;
&lt;P&gt;How precisely did you determine some UDP traffic wasn't logged?&lt;BR /&gt;Is the traffic that you're seeing as "not logged" related to SIP?&lt;BR /&gt;What precise Access Policy rules are allowing the traffic?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 23:09:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-traffic-not-showing-up-in-the-logs/m-p/165231#M29619</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-12-14T23:09:33Z</dc:date>
    </item>
    <item>
      <title>Re: Some traffic not showing up in the logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-traffic-not-showing-up-in-the-logs/m-p/165233#M29620</link>
      <description>&lt;P&gt;One known occurrence would be if the same traffic was being seen by the gateway twice unexpectedly (&lt;SPAN&gt;sk172204)&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;but that's not specific to VoIP rather a topology or routing issue.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 23:58:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-traffic-not-showing-up-in-the-logs/m-p/165233#M29620</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-12-14T23:58:14Z</dc:date>
    </item>
    <item>
      <title>Re: Some traffic not showing up in the logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-traffic-not-showing-up-in-the-logs/m-p/165234#M29621</link>
      <description>&lt;P&gt;Which JHF take is installed?&lt;/P&gt;
&lt;P&gt;T75 or higher fixes an issue with VOIP (MGCP) traffic PRJ-40930,&lt;SPAN&gt;PRJ-40928&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Additionally sk177365 is also going to be addressed in an upcoming take refer&amp;nbsp;&lt;SPAN&gt;PRJ-28732,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;PRHF-11703.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;To verify if either is relevant please consult TAC to debug further.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 00:05:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-traffic-not-showing-up-in-the-logs/m-p/165234#M29621</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-12-15T00:05:03Z</dc:date>
    </item>
  </channel>
</rss>

