<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: START_CONNECTION or END_CONNECTION in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/START-CONNECTION-or-END-CONNECTION/m-p/225045#M43298</link>
    <description>&lt;P&gt;Never seen that link, thats super USEFUL.&lt;/P&gt;
&lt;P&gt;Thanks brother &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Thu, 29 Aug 2024 20:14:52 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-08-29T20:14:52Z</dc:date>
    <item>
      <title>START_CONNECTION or END_CONNECTION</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/START-CONNECTION-or-END-CONNECTION/m-p/224968#M43271</link>
      <description>&lt;P&gt;Does check point log START_CONNECTION or END_CONNECTION in their logs?&amp;nbsp; &amp;nbsp; I'm just seeing SSH version2 traffic, but NOT START or END_CONNECTION.&amp;nbsp; Am I missing something?&amp;nbsp; &amp;nbsp; I may need more extensive logging (accounting) or a capture packet for that, correct?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Id: c107fa67-d9a7-b6fc-66be-cd5d00010006&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Marker: @A@@B@1723776012@C@2042288&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Log Server Origin: 172.bb.XX.XX&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Time: 2024-08-16T03:54:05Z&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Interface Direction: inbound&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Interface Name: eth10&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Id Generated By Indexer: false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;First: true&lt;/SPAN&gt;&lt;BR /&gt;&lt;STRONG&gt;Sequencenum: 125&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;Source Zone: External&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Destination Zone: Internal&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Service ID: ssh_version_2&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Source: IPa&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Source Port: 39892&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Destination: IPb&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Destination Port: 22&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;IP Protocol: 6&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Xlate (NAT) Destination IP: someIP&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Xlate (NAT) Source Port: 0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Xlate (NAT) Destination Port:0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;NAT Rule Number: 165&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;NAT Additional Rule Number: 0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Nat Rule Uid: a56039b0-dc01-4b9a-896d-cc5f00aa0511&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Action: Accept&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Type: Connection&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Policy Name: policy&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Policy Management: colorm&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Db Tag: {68C9D707-6C15-F940-88CE-0A3F4A66CC6F}&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Policy Date: 2024-08-15T15:26:06Z&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Blade: Firewall&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Origin: colorN&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Service: TCP/22&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Product Family: Access&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Logid: 0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Access Rule Name: autoloader transfers&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Access Rule Number: 26&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Policy Rule UID: c0209209-a428-4dbb-88f8-2b89c774cf72&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Layer Name: Security&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Interface: eth10&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Description: ssh_version_2 Traffic Accepted from someIP&amp;nbsp; to aIP&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Id: 78f4c07f-b81c-6cdf-66be-cd5d00010004&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Marker: @A@@B@1723776012@C@2042219&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Log Server Origin: IPA&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Time: 2024-08-16T03:54:05Z&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Interface Direction: inbound&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Interface Name: eth10&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Id Generated By Indexer: false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;First: true&lt;/SPAN&gt;&lt;BR /&gt;&lt;STRONG&gt;Sequencenum: 107&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;Source Zone: External&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Destination Zone: Internal&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Service ID: ssh_version_2&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Source: IPB&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Source Port: 38657&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Destination: IPC&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Destination Port: 22&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;IP Protocol: 6&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Xlate (NAT) Destination IP: someIP&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Xlate (NAT) Source Port: 0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Xlate (NAT) Destination Port:0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;NAT Rule Number: 165&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;NAT Additional Rule Number: 0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Nat Rule Uid: a56039b0-dc01-4b9a-896d-cc5f00aa0511&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Action: Accept&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Type: Connection&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Policy Name: pname&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Policy Management: colorM&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Db Tag: {68C9D707-6C15-F940-88CE-0A3F4A66CC6F}&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Policy Date: 2024-08-15T15:26:06Z&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Blade: Firewall&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Origin: colorN&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Service: TCP/22&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Product Family: Access&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Logid: 0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Access oader transfers&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Access Rule Number: 26&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Policy Rule UID: c0209209-a428-4dbb-88f8-2b89c774cf72&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Layer Name: rity&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Interface: eth10&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Description: ssh_version_2 Traffic Accepted from 1 to 2&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 12:46:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/START-CONNECTION-or-END-CONNECTION/m-p/224968#M43271</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2024-08-29T12:46:50Z</dc:date>
    </item>
    <item>
      <title>Re: START_CONNECTION or END_CONNECTION</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/START-CONNECTION-or-END-CONNECTION/m-p/224974#M43274</link>
      <description>&lt;P&gt;From Phoneboy:&lt;/P&gt;
&lt;P&gt;"&lt;SPAN&gt;When you enable accounting on a rule (which must be done per rule), it logs the bytes/duration of the relevant flow.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;In general this data is updated every 10 minutes and after the connection closes."&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Log-accounting/m-p/110407#M15221" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Log-accounting/m-p/110407#M15221&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Akos&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 12:55:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/START-CONNECTION-or-END-CONNECTION/m-p/224974#M43274</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-08-29T12:55:33Z</dc:date>
    </item>
    <item>
      <title>Re: START_CONNECTION or END_CONNECTION</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/START-CONNECTION-or-END-CONNECTION/m-p/225045#M43298</link>
      <description>&lt;P&gt;Never seen that link, thats super USEFUL.&lt;/P&gt;
&lt;P&gt;Thanks brother &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 20:14:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/START-CONNECTION-or-END-CONNECTION/m-p/225045#M43298</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-29T20:14:52Z</dc:date>
    </item>
    <item>
      <title>Re: START_CONNECTION or END_CONNECTION</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/START-CONNECTION-or-END-CONNECTION/m-p/225046#M43299</link>
      <description>&lt;P&gt;Hey bud, for the context, I figured would also share this link.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_LoggingAndMonitoring_AdminGuide/Topics-LMG/Tracking-Options.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_LoggingAndMonitoring_AdminGuide/Topics-LMG/Tracking-Options.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 20:16:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/START-CONNECTION-or-END-CONNECTION/m-p/225046#M43299</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-29T20:16:21Z</dc:date>
    </item>
  </channel>
</rss>

