<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: No logs in Firewall &amp; Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-Security-Management/No-logs/m-p/215884#M65166</link>
    <description>&lt;P&gt;Those are ONLY logs you dont see?&lt;/P&gt;</description>
    <pubDate>Fri, 31 May 2024 09:59:38 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-05-31T09:59:38Z</dc:date>
    <item>
      <title>No logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/No-logs/m-p/215874#M65165</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;The case is as follows: We have a specific source address and a specific destination address. There is no problem with communication, but there are no logs. Logging is turned on. The IP addresses are on different networks, so traffic should go through the gateway. When we ping others' destination IP address, we see logs. Any ideas why we can't see the logs for specific addresses? What can we check or change?&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Mateusz&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 09:04:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/No-logs/m-p/215874#M65165</guid>
      <dc:creator>KomisarzRyba</dc:creator>
      <dc:date>2024-05-31T09:04:18Z</dc:date>
    </item>
    <item>
      <title>Re: No logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/No-logs/m-p/215884#M65166</link>
      <description>&lt;P&gt;Those are ONLY logs you dont see?&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 09:59:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/No-logs/m-p/215884#M65166</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-31T09:59:38Z</dc:date>
    </item>
    <item>
      <title>Re: No logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/No-logs/m-p/215885#M65167</link>
      <description>&lt;P&gt;Yes, those are only logs I don't see.&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 10:03:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/No-logs/m-p/215885#M65167</guid>
      <dc:creator>KomisarzRyba</dc:creator>
      <dc:date>2024-05-31T10:03:43Z</dc:date>
    </item>
    <item>
      <title>Re: No logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/No-logs/m-p/215928#M65168</link>
      <description>&lt;P&gt;Have you confirmed with a tcpdump and/or a traceroute that the traffic is actually passing through the gateway?&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 14:44:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/No-logs/m-p/215928#M65168</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-05-31T14:44:18Z</dc:date>
    </item>
    <item>
      <title>Re: No logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/No-logs/m-p/215964#M65169</link>
      <description>&lt;P&gt;I second what Phoneboy said, you need to verify with tcpdump if its even reaching the gateway. Though, I assume it must be, since you said ping is fine, but nothing else. Did you try maybe old school tracker to see if that works?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 19:57:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/No-logs/m-p/215964#M65169</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-31T19:57:11Z</dc:date>
    </item>
    <item>
      <title>Re: No logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/No-logs/m-p/216108#M65170</link>
      <description>&lt;P&gt;This might be matched on another rule in the rule base than other protocols.&lt;/P&gt;
&lt;P&gt;I would suggest checking if all relevant rules have logging and also try to turn on logging of implied rules:&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 698px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26024i99CD15CFD57432DB/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Jun 2024 08:34:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/No-logs/m-p/216108#M65170</guid>
      <dc:creator>Amir_Senn</dc:creator>
      <dc:date>2024-06-02T08:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: No logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/No-logs/m-p/216191#M65171</link>
      <description>&lt;P&gt;Here we can see the result of the ping and tracert test.&lt;BR /&gt;Src: 172.21.1.60,&lt;BR /&gt;Dst: 172.21.16.201&lt;BR /&gt;CheckPoint interface IP address: 172.21.0.1/20&lt;BR /&gt;Below we can see logs from pinging other addresses. These logs can be seen in Smartconsola. There are no logs to the destination address.&lt;BR /&gt;&lt;SPAN&gt;All rules have logging enabled. Log Implied Rules are enabled.&lt;BR /&gt;&lt;/SPAN&gt;Any ideas?&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Zrzut ekranu 2024-05-24 120046.pngdsa.png" style="width: 500px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26043i96B7AAEB34427C7F/image-size/large?v=v2&amp;amp;px=999" role="button" title="Zrzut ekranu 2024-05-24 120046.pngdsa.png" alt="Zrzut ekranu 2024-05-24 120046.pngdsa.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Zrzut ekranu 2024-05-24 120319.pngdsa.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26042i3E8152D6F154544F/image-size/large?v=v2&amp;amp;px=999" role="button" title="Zrzut ekranu 2024-05-24 120319.pngdsa.png" alt="Zrzut ekranu 2024-05-24 120319.pngdsa.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 09:30:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/No-logs/m-p/216191#M65171</guid>
      <dc:creator>KomisarzRyba</dc:creator>
      <dc:date>2024-06-03T09:30:04Z</dc:date>
    </item>
    <item>
      <title>Re: No logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/No-logs/m-p/216192#M65172</link>
      <description>&lt;P&gt;From the looks of it logs might not behave the same since this is also relates to VPN. For ping we would usually expect firewall blade. Also this is not the actual ping since this is not the same IP as dst, those look like remote GW in the VPN community?&lt;/P&gt;
&lt;P&gt;Also you have hops missing in the tracert? This might happen because of VPN encryption.&lt;/P&gt;
&lt;P&gt;If you try to use tcpdump, check which port/service. Probably VPN ports/services.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 09:58:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/No-logs/m-p/216192#M65172</guid>
      <dc:creator>Amir_Senn</dc:creator>
      <dc:date>2024-06-03T09:58:04Z</dc:date>
    </item>
    <item>
      <title>Re: No logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/No-logs/m-p/219934#M65173</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Yes, the traffic is passing through the gateway - c&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;onfirmed with a tcpdump.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2024 13:52:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/No-logs/m-p/219934#M65173</guid>
      <dc:creator>KomisarzRyba</dc:creator>
      <dc:date>2024-07-08T13:52:25Z</dc:date>
    </item>
    <item>
      <title>Re: No logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/No-logs/m-p/219949#M65174</link>
      <description>&lt;P&gt;Try "old school" tracker, if that works, then its most likely indexing issue.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26645i50414AAA2BF6AF2C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2024 14:37:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/No-logs/m-p/219949#M65174</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-08T14:37:10Z</dc:date>
    </item>
    <item>
      <title>Re: No logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/No-logs/m-p/219952#M65175</link>
      <description>&lt;P&gt;Alsso, make sure this is enabled on mgmt server object.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26646iC77A66B2DEEF29F5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_2.png" alt="Screenshot_2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2024 14:43:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/No-logs/m-p/219952#M65175</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-08T14:43:33Z</dc:date>
    </item>
    <item>
      <title>Re: No logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/No-logs/m-p/220357#M65176</link>
      <description>&lt;P&gt;&lt;SPAN&gt;The problem was solved by replacing the device with a newer one.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2024 07:07:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/No-logs/m-p/220357#M65176</guid>
      <dc:creator>KomisarzRyba</dc:creator>
      <dc:date>2024-07-11T07:07:11Z</dc:date>
    </item>
  </channel>
</rss>

