<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I don't see information in SmartEvent reports - Firewall Bridge Mode in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/I-don-t-see-information-in-SmartEvent-reports-Firewall-Bridge/m-p/167004#M30133</link>
    <description>&lt;P&gt;Apologies I should have read more closely, how much load is the machine under?&lt;/P&gt;
&lt;P&gt;Do you have enough information from the logs to be able to "define" the internal network for the&amp;nbsp; SmartEvent policy or at least test with a relevant RFC1918 range?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SE Policy.png" style="width: 312px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19029iB00B0C188D21948F/image-size/large?v=v2&amp;amp;px=999" role="button" title="SE Policy.png" alt="SE Policy.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Internal_Network.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19030i7FDC1D9B5E5DCB70/image-size/large?v=v2&amp;amp;px=999" role="button" title="Internal_Network.png" alt="Internal_Network.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 08 Jan 2023 00:56:30 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2023-01-08T00:56:30Z</dc:date>
    <item>
      <title>I don't see information in SmartEvent reports - Firewall Bridge Mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/I-don-t-see-information-in-SmartEvent-reports-Firewall-Bridge/m-p/166975#M30122</link>
      <description>&lt;P&gt;Hello everyone!&lt;/P&gt;&lt;P&gt;I have an issue with some SmartEvent reports on a firewall that is operating in bridge mode, in standalone operation mode and with R81.10 JHF 79 GA.&lt;/P&gt;&lt;P&gt;The model of the firewall is a 5600 which basically has the following on its interfaces:&lt;BR /&gt;*Mmgt interface - for firewall management.&lt;BR /&gt;*Bridge interface composed by interface eth1 (for inbound traffic) and eth2 (for outbound traffic) [defining eth1 as internal interface and eth2 as external interface in anti-spoofing].&lt;BR /&gt;The source traffic comes from a corporate office and sends the traffic to a Backup as a Service provider, this is the traffic that passes through the bridge interfaces. Basically a bridge for a "LAN" type network.&lt;/P&gt;&lt;P&gt;I am trying to generate some SmartEvent reports such as "Network Activity", "Threat Prevention" or any other type of report, however when I put the report for the last 7 days, 24 hours or any time range, the reports do not contain any information and generate empty reports.&lt;/P&gt;&lt;P&gt;In the firewall I have the Monitoring (advanced networking) blades, SmartEvent Server, SmartEvent Correlation Unit and log indexing is enabled.&lt;/P&gt;&lt;P&gt;I tried to turn off the mentioned blades and turn them on again, installing database and policies, I stopped the smartevent services in CLI with evstop, evstart, but in none of these tests I got any difference or any result in the reports.&lt;/P&gt;&lt;P&gt;I have even run a cpstop, cpstart and I haven't seen any results in the SmartEvent reports either.&lt;/P&gt;&lt;P&gt;The strange thing is that I can see the logs of the connections that pass through the firewall without any problem, I see traffic through the br1 with a tcpdump by CLI, I don't see any traffic dropped by "fw ctl zdebug + drop", I have an accept any-any rule, but still, I don't see any results in the reports.&lt;/P&gt;&lt;P&gt;Has anyone had something similar happen? or any idea?&lt;/P&gt;&lt;P&gt;Greetings to all!&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jan 2023 05:16:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/I-don-t-see-information-in-SmartEvent-reports-Firewall-Bridge/m-p/166975#M30122</guid>
      <dc:creator>israelsc</dc:creator>
      <dc:date>2023-01-07T05:16:37Z</dc:date>
    </item>
    <item>
      <title>Re: I don't see information in SmartEvent reports - Firewall Bridge Mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/I-don-t-see-information-in-SmartEvent-reports-Firewall-Bridge/m-p/166976#M30123</link>
      <description>&lt;P&gt;&lt;SPAN&gt;W&lt;/SPAN&gt;&lt;SPAN&gt;hat level of logging is configured in the "track" column - Detailed or Extended?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;In the Track Column, click on the drop down menu &amp;gt; more.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Change the Track Settings from Log to Detailed or Extended.&lt;/P&gt;
&lt;P&gt;Install the policy.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jan 2023 05:44:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/I-don-t-see-information-in-SmartEvent-reports-Firewall-Bridge/m-p/166976#M30123</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-01-07T05:44:06Z</dc:date>
    </item>
    <item>
      <title>Re: I don't see information in SmartEvent reports - Firewall Bridge Mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/I-don-t-see-information-in-SmartEvent-reports-Firewall-Bridge/m-p/166980#M30126</link>
      <description>&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;I have the simple "Log" configuration, without "Detailed" or Extended.&lt;BR /&gt;I also do not have "Accounting" enabled.&lt;BR /&gt;I have attached a screenshot of this.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rule configuration.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19028i4D1C10EC08CB938D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="rule configuration.png" alt="rule configuration.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The reason why there is an "any-any" rule is because it is a Poc. My customer has not given us the networks to define them in rules.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Sat, 07 Jan 2023 05:38:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/I-don-t-see-information-in-SmartEvent-reports-Firewall-Bridge/m-p/166980#M30126</guid>
      <dc:creator>israelsc</dc:creator>
      <dc:date>2023-01-07T05:38:35Z</dc:date>
    </item>
    <item>
      <title>Re: I don't see information in SmartEvent reports - Firewall Bridge Mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/I-don-t-see-information-in-SmartEvent-reports-Firewall-Bridge/m-p/166981#M30127</link>
      <description>&lt;P&gt;Which reports are you trying to run?&lt;/P&gt;
&lt;P&gt;Many will rely on details from AppC logs requiring the change suggested above.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jan 2023 06:01:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/I-don-t-see-information-in-SmartEvent-reports-Firewall-Bridge/m-p/166981#M30127</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-01-07T06:01:48Z</dc:date>
    </item>
    <item>
      <title>Re: I don't see information in SmartEvent reports - Firewall Bridge Mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/I-don-t-see-information-in-SmartEvent-reports-Firewall-Bridge/m-p/167003#M30132</link>
      <description>&lt;P&gt;I'm trying to run the reports templates that the system has by default, for example "Network Activity" of type 'Access Control' or the "IPS" report of type "Threat Prevention", but in none of them I get results.&lt;BR /&gt;It should be noted that I have the firewall, IPS, Anti-Bot, Antivirus blades on. So, in theory it should show me information.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jan 2023 17:26:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/I-don-t-see-information-in-SmartEvent-reports-Firewall-Bridge/m-p/167003#M30132</guid>
      <dc:creator>israelsc</dc:creator>
      <dc:date>2023-01-07T17:26:56Z</dc:date>
    </item>
    <item>
      <title>Re: I don't see information in SmartEvent reports - Firewall Bridge Mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/I-don-t-see-information-in-SmartEvent-reports-Firewall-Bridge/m-p/167004#M30133</link>
      <description>&lt;P&gt;Apologies I should have read more closely, how much load is the machine under?&lt;/P&gt;
&lt;P&gt;Do you have enough information from the logs to be able to "define" the internal network for the&amp;nbsp; SmartEvent policy or at least test with a relevant RFC1918 range?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SE Policy.png" style="width: 312px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19029iB00B0C188D21948F/image-size/large?v=v2&amp;amp;px=999" role="button" title="SE Policy.png" alt="SE Policy.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Internal_Network.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19030i7FDC1D9B5E5DCB70/image-size/large?v=v2&amp;amp;px=999" role="button" title="Internal_Network.png" alt="Internal_Network.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Jan 2023 00:56:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/I-don-t-see-information-in-SmartEvent-reports-Firewall-Bridge/m-p/167004#M30133</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-01-08T00:56:30Z</dc:date>
    </item>
    <item>
      <title>Re: I don't see information in SmartEvent reports - Firewall Bridge Mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/I-don-t-see-information-in-SmartEvent-reports-Firewall-Bridge/m-p/167007#M30134</link>
      <description>&lt;P&gt;At the moment my customer has not provided me with the information about their internal networks, but I will try to get this information and define it in the firewall rules to see if it makes any difference in the reports.&lt;/P&gt;</description>
      <pubDate>Sun, 08 Jan 2023 01:43:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/I-don-t-see-information-in-SmartEvent-reports-Firewall-Bridge/m-p/167007#M30134</guid>
      <dc:creator>israelsc</dc:creator>
      <dc:date>2023-01-08T01:43:23Z</dc:date>
    </item>
  </channel>
</rss>

