<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Avoid tracking connection but still log sk113479 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Avoid-tracking-connection-but-still-log-sk113479/m-p/197682#M66791</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;we will set no-log on all layers and try again.&lt;/P&gt;&lt;P&gt;Otherwise we will open the TAC case.&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;&lt;P&gt;F&lt;/P&gt;</description>
    <pubDate>Fri, 10 Nov 2023 11:04:45 GMT</pubDate>
    <dc:creator>frenzetti</dc:creator>
    <dc:date>2023-11-10T11:04:45Z</dc:date>
    <item>
      <title>Avoid tracking connection but still log sk113479</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Avoid-tracking-connection-but-still-log-sk113479/m-p/197013#M66781</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We need to allow users to reach a certain site but avoid tracking the connection.&lt;BR /&gt;We created a rule setting logging to "none" but the console displays the error &lt;EM&gt;Connection terminated before the Security Gateway was able to make a decision: Insufficient data passed. To learn more see sk113479.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Connection starts in http and then switches to https. Only http traffic (with the error) is logged. Https is correctly not tracked&lt;BR /&gt;&lt;BR /&gt;Has anyone found themselves in the same situation and managed to resolve it?&lt;/P&gt;&lt;P&gt;Release is 81.10, blade are firewall and application control&lt;/P&gt;&lt;P&gt;Thx for your support&lt;/P&gt;&lt;P&gt;F&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 09:43:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Avoid-tracking-connection-but-still-log-sk113479/m-p/197013#M66781</guid>
      <dc:creator>frenzetti</dc:creator>
      <dc:date>2023-11-03T09:43:41Z</dc:date>
    </item>
    <item>
      <title>Re: Avoid tracking connection but still log sk113479</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Avoid-tracking-connection-but-still-log-sk113479/m-p/197068#M66782</link>
      <description>&lt;P&gt;What does the rule that permits the traffic look like?&lt;BR /&gt;Unless it contains http explicitly (the service), this is expected behavior.&lt;BR /&gt;To resolve the issue, add http to the the Services for the relevant rule (or create a new one).&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 19:18:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Avoid-tracking-connection-but-still-log-sk113479/m-p/197068#M66782</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-11-03T19:18:21Z</dc:date>
    </item>
    <item>
      <title>Re: Avoid tracking connection but still log sk113479</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Avoid-tracking-connection-but-still-log-sk113479/m-p/197272#M66783</link>
      <description>&lt;P&gt;Hi&amp;nbsp; &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt; , thx for your response.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Rule number 1 (above all) looks like this:&lt;/P&gt;&lt;P&gt;Source = Any&lt;BR /&gt;Destination = IP Address Object&lt;BR /&gt;Services = http,https&lt;BR /&gt;Log = None&lt;BR /&gt;Install On = Target Cluster&lt;BR /&gt;&lt;BR /&gt;Still logging&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 08:05:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Avoid-tracking-connection-but-still-log-sk113479/m-p/197272#M66783</guid>
      <dc:creator>frenzetti</dc:creator>
      <dc:date>2023-11-07T08:05:46Z</dc:date>
    </item>
    <item>
      <title>Re: Avoid tracking connection but still log sk113479</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Avoid-tracking-connection-but-still-log-sk113479/m-p/197336#M66784</link>
      <description>&lt;P&gt;Can you provide a full log card (with sensitive details redacted)?&lt;BR /&gt;I suspect this may be a bug of some sort and will require TAC to assist: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 15:41:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Avoid-tracking-connection-but-still-log-sk113479/m-p/197336#M66784</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-11-07T15:41:12Z</dc:date>
    </item>
    <item>
      <title>Re: Avoid tracking connection but still log sk113479</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Avoid-tracking-connection-but-still-log-sk113479/m-p/197338#M66785</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/12119"&gt;@Daphne_Reese&lt;/a&gt; , what is exactly needed (when you say 'full log card')&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 15:54:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Avoid-tracking-connection-but-still-log-sk113479/m-p/197338#M66785</guid>
      <dc:creator>frenzetti</dc:creator>
      <dc:date>2023-11-07T15:54:58Z</dc:date>
    </item>
    <item>
      <title>Re: Avoid tracking connection but still log sk113479</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Avoid-tracking-connection-but-still-log-sk113479/m-p/197353#M66786</link>
      <description>&lt;P&gt;When you double-click on an individual log entry, you will see a screen pop up with more details; This is the log card.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 20:19:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Avoid-tracking-connection-but-still-log-sk113479/m-p/197353#M66786</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-11-07T20:19:03Z</dc:date>
    </item>
    <item>
      <title>Re: Avoid tracking connection but still log sk113479</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Avoid-tracking-connection-but-still-log-sk113479/m-p/197436#M66787</link>
      <description>&lt;P&gt;Hi, today we splitted the rule.&lt;/P&gt;&lt;P&gt;Rule 1 for service HTTP, Drop, No-Log&lt;/P&gt;&lt;P&gt;Rule 2 switched Services to ANY, Accept, No-Log (Any protocol: ping, https, ntp, etc)&lt;/P&gt;&lt;P&gt;Rule Number 1 is matched and no log is present for HTTP - that's ok&lt;/P&gt;&lt;P&gt;For HTTPS, as you can see, matched rule is exactly number 2 but still logging&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Log.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23105i9438A13BFB697C9B/image-size/large?v=v2&amp;amp;px=999" role="button" title="Log.png" alt="Log.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 13:31:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Avoid-tracking-connection-but-still-log-sk113479/m-p/197436#M66787</guid>
      <dc:creator>frenzetti</dc:creator>
      <dc:date>2023-11-08T13:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: Avoid tracking connection but still log sk113479</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Avoid-tracking-connection-but-still-log-sk113479/m-p/197496#M66788</link>
      <description>&lt;P&gt;What is the precise destination here?&lt;BR /&gt;Is it the gateway or something else?&lt;BR /&gt;What about using the explicit https service in Rule 2?&lt;BR /&gt;Are there other ordered Access Policy layers in use or just the one?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 19:42:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Avoid-tracking-connection-but-still-log-sk113479/m-p/197496#M66788</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-11-08T19:42:57Z</dc:date>
    </item>
    <item>
      <title>Re: Avoid tracking connection but still log sk113479</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Avoid-tracking-connection-but-still-log-sk113479/m-p/197602#M66789</link>
      <description>&lt;P&gt;&lt;SPAN&gt;What is the precise destination here? &lt;STRONG&gt;Destination is an IP Address (in rule we put IP Address Object)&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Is it the gateway or something else? &lt;STRONG&gt;External WebSite&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;What about using the explicit https service in Rule 2? &lt;STRONG&gt;Tried without success&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Are there other ordered Access Policy layers in use or just the one? &lt;STRONG&gt;URL/App filtering with allow policy but no log about AppControl blade&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 14:42:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Avoid-tracking-connection-but-still-log-sk113479/m-p/197602#M66789</guid>
      <dc:creator>frenzetti</dc:creator>
      <dc:date>2023-11-09T14:42:07Z</dc:date>
    </item>
    <item>
      <title>Re: Avoid tracking connection but still log sk113479</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Avoid-tracking-connection-but-still-log-sk113479/m-p/197639#M66790</link>
      <description>&lt;P&gt;If the rule that is matched in the other layer is set to log, the connection will be logged.&lt;BR /&gt;This is expected behavior.&lt;BR /&gt;If this isn't the case, I recommend a TAC case: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 21:20:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Avoid-tracking-connection-but-still-log-sk113479/m-p/197639#M66790</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-11-09T21:20:55Z</dc:date>
    </item>
    <item>
      <title>Re: Avoid tracking connection but still log sk113479</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Avoid-tracking-connection-but-still-log-sk113479/m-p/197682#M66791</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;we will set no-log on all layers and try again.&lt;/P&gt;&lt;P&gt;Otherwise we will open the TAC case.&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;&lt;P&gt;F&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2023 11:04:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Avoid-tracking-connection-but-still-log-sk113479/m-p/197682#M66791</guid>
      <dc:creator>frenzetti</dc:creator>
      <dc:date>2023-11-10T11:04:45Z</dc:date>
    </item>
  </channel>
</rss>

