<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Separate log record for each packet of ping / ICMP / Echo in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Separate-log-record-for-each-packet-of-ping-ICMP-Echo/m-p/196911#M36735</link>
    <description>&lt;OL&gt;
&lt;LI&gt;No, you shouldn't expect a log for each request.&lt;/LI&gt;
&lt;LI&gt;Yes, the timeout which controls this is Global Properties &amp;gt; Stateful Inspection &amp;gt; ICMP virtual session timeout. Note that it is in integer seconds, and there is no way to specify fractional seconds.&lt;/LI&gt;
&lt;LI&gt;There is no good way to cause the firewall to log every ICMP packet.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Why do you think you need to do this? It seems like a very strange goal.&lt;/P&gt;</description>
    <pubDate>Thu, 02 Nov 2023 13:33:55 GMT</pubDate>
    <dc:creator>Bob_Zimmerman</dc:creator>
    <dc:date>2023-11-02T13:33:55Z</dc:date>
    <item>
      <title>Separate log record for each packet of ping / ICMP / Echo</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Separate-log-record-for-each-packet-of-ping-ICMP-Echo/m-p/196878#M36730</link>
      <description>&lt;P&gt;The scenario: multiple pings / icmp / echo requests sent via checkpoint firewall,&amp;nbsp;&lt;/P&gt;&lt;P&gt;The need: Log each request separately&amp;nbsp;&lt;/P&gt;&lt;P&gt;Questions:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Should I expect a separate&amp;nbsp; log record for each ping / ICMP / Echo in traffic logs?&lt;/LI&gt;&lt;LI&gt;What configuration may be used regarding this topic and what would be the impact? For example&amp;nbsp;&lt;SPAN&gt;icmp virtual session timeout&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;How can I configure the firewall to log every request?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Thx&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 09:30:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Separate-log-record-for-each-packet-of-ping-ICMP-Echo/m-p/196878#M36730</guid>
      <dc:creator>Emil_T</dc:creator>
      <dc:date>2023-11-02T09:30:42Z</dc:date>
    </item>
    <item>
      <title>Re: Separate log record for each packet of ping / ICMP / Echo</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Separate-log-record-for-each-packet-of-ping-ICMP-Echo/m-p/196911#M36735</link>
      <description>&lt;OL&gt;
&lt;LI&gt;No, you shouldn't expect a log for each request.&lt;/LI&gt;
&lt;LI&gt;Yes, the timeout which controls this is Global Properties &amp;gt; Stateful Inspection &amp;gt; ICMP virtual session timeout. Note that it is in integer seconds, and there is no way to specify fractional seconds.&lt;/LI&gt;
&lt;LI&gt;There is no good way to cause the firewall to log every ICMP packet.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Why do you think you need to do this? It seems like a very strange goal.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 13:33:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Separate-log-record-for-each-packet-of-ping-ICMP-Echo/m-p/196911#M36735</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-11-02T13:33:55Z</dc:date>
    </item>
    <item>
      <title>Re: Separate log record for each packet of ping / ICMP / Echo</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Separate-log-record-for-each-packet-of-ping-ICMP-Echo/m-p/196912#M36736</link>
      <description>&lt;P&gt;As above I wouldn't recommend this, why is it a requirement for you?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 13:36:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Separate-log-record-for-each-packet-of-ping-ICMP-Echo/m-p/196912#M36736</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-11-02T13:36:28Z</dc:date>
    </item>
    <item>
      <title>Re: Separate log record for each packet of ping / ICMP / Echo</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Separate-log-record-for-each-packet-of-ping-ICMP-Echo/m-p/196923#M36739</link>
      <description>&lt;P&gt;Having a separate log for every ICMP packet that is part of the same ping tracked "session" is not generally something that you want; keep in mind that setting Accounting on the rule matching the ping traffic would give you byte and packet totals for the duration of the ping session.&lt;/P&gt;
&lt;P&gt;However you could make sure that echo-request is freely allowed by your Access Control policy, then in Threat Prevention create a custom Indicator for ABOT that will match the ping traffic you want (by IP address or whatever) and have it issue a log (and even grab a packet capture) for each ICMP packet.&amp;nbsp; However this could substantially increase the logging load on the firewall and I'd not recommend trying it.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 14:56:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Separate-log-record-for-each-packet-of-ping-ICMP-Echo/m-p/196923#M36739</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-11-02T14:56:45Z</dc:date>
    </item>
    <item>
      <title>Re: Separate log record for each packet of ping / ICMP / Echo</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Separate-log-record-for-each-packet-of-ping-ICMP-Echo/m-p/196959#M36748</link>
      <description>&lt;P&gt;Do not expect more than one log per minute for any given connection attempt, regardless of method, without adjusting the Excessive Log Grace Period in Global Properties:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 550px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23035iE2C9A8E5ED77503C/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;This applies to every type of connection and goes back to the very earliest days of the product.&lt;BR /&gt;Any change to this will require a policy installation.&lt;BR /&gt;Adjusting this parameter too low will likely have a performance impact and it's not recommended.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 18:20:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Separate-log-record-for-each-packet-of-ping-ICMP-Echo/m-p/196959#M36748</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-11-02T18:20:47Z</dc:date>
    </item>
    <item>
      <title>Re: Separate log record for each packet of ping / ICMP / Echo</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Separate-log-record-for-each-packet-of-ping-ICMP-Echo/m-p/196976#M36753</link>
      <description>&lt;P&gt;I need this to troubleshoot and analyze network issues that recently occurred.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to see whether each echo request sent from server, arrived and allowed via the firewall.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 20:35:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Separate-log-record-for-each-packet-of-ping-ICMP-Echo/m-p/196976#M36753</guid>
      <dc:creator>Emil_T</dc:creator>
      <dc:date>2023-11-02T20:35:27Z</dc:date>
    </item>
    <item>
      <title>Re: Separate log record for each packet of ping / ICMP / Echo</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Separate-log-record-for-each-packet-of-ping-ICMP-Echo/m-p/196994#M36757</link>
      <description>&lt;P&gt;Other tools such as fw monitor / cppcap / tcpdump might be more helpful in this context.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 04:08:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Separate-log-record-for-each-packet-of-ping-ICMP-Echo/m-p/196994#M36757</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-11-03T04:08:49Z</dc:date>
    </item>
    <item>
      <title>Re: Separate log record for each packet of ping / ICMP / Echo</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Separate-log-record-for-each-packet-of-ping-ICMP-Echo/m-p/197079#M36768</link>
      <description>&lt;P&gt;Yes, but such tools are only useful AFTER the you know what to look for. What I needed in this case is backward logs.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 20:49:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Separate-log-record-for-each-packet-of-ping-ICMP-Echo/m-p/197079#M36768</guid>
      <dc:creator>Emil_T</dc:creator>
      <dc:date>2023-11-03T20:49:27Z</dc:date>
    </item>
  </channel>
</rss>

