<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why differents interfaces in logs that concern to one rule? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-differents-interfaces-in-logs-that-concern-to-one-rule/m-p/36427#M2969</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What you're seeing&amp;nbsp;in the logs are sessions, which correlate data across several connections.&lt;/P&gt;&lt;P&gt;As to why it's logging LAN versus WAN sometimes, it may be related to the first packet seen&amp;nbsp;on session correlation, which is based on (in)activity.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 19 Oct 2018 16:36:49 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-10-19T16:36:49Z</dc:date>
    <item>
      <title>Why differents interfaces in logs that concern to one rule?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-differents-interfaces-in-logs-that-concern-to-one-rule/m-p/36426#M2968</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Saludos.... we have a 1490 smb appliance as perimeter firewall. Two devices at LAN (192.168.3.8, 192.168.3.9) connect to a server (13.82.177.x). ...but I have doubts about logs:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;even though each device connect to server more than once in a period of time, appliance only logs one time. I am sure that it makes more than one connection, because in each one,, an email is received, and I have the precaution of waiting to receive such email before "firing" another event that causes a connection&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Why in the logs the interface WAN appears in one occasion and in another the LAN? randomly I do not think ... but I can not find the pattern !!&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is worth mentioning that the logs are saved in a sdcard memory inserted in the appliance, and recently had to be reinserted because the logs were not being saved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!!&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/71663_pastedImage_2.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Oct 2018 17:03:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-differents-interfaces-in-logs-that-concern-to-one-rule/m-p/36426#M2968</guid>
      <dc:creator>LuisSP</dc:creator>
      <dc:date>2018-10-18T17:03:29Z</dc:date>
    </item>
    <item>
      <title>Re: Why differents interfaces in logs that concern to one rule?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-differents-interfaces-in-logs-that-concern-to-one-rule/m-p/36427#M2969</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What you're seeing&amp;nbsp;in the logs are sessions, which correlate data across several connections.&lt;/P&gt;&lt;P&gt;As to why it's logging LAN versus WAN sometimes, it may be related to the first packet seen&amp;nbsp;on session correlation, which is based on (in)activity.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Oct 2018 16:36:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-differents-interfaces-in-logs-that-concern-to-one-rule/m-p/36427#M2969</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-10-19T16:36:49Z</dc:date>
    </item>
  </channel>
</rss>

