<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic possible to filter logs by geo location policy in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/possible-to-filter-logs-by-geo-location-policy/m-p/143531#M72741</link>
    <description>&lt;P&gt;can i create log filter that only shows traffic blocked "dropped" because of&amp;nbsp;Geo-location inbound enforcement?&lt;/P&gt;&lt;P&gt;Log server is R81.10&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 11 Mar 2022 16:25:13 GMT</pubDate>
    <dc:creator>nflnetwork29</dc:creator>
    <dc:date>2022-03-11T16:25:13Z</dc:date>
    <item>
      <title>possible to filter logs by geo location policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/possible-to-filter-logs-by-geo-location-policy/m-p/143531#M72741</link>
      <description>&lt;P&gt;can i create log filter that only shows traffic blocked "dropped" because of&amp;nbsp;Geo-location inbound enforcement?&lt;/P&gt;&lt;P&gt;Log server is R81.10&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 16:25:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/possible-to-filter-logs-by-geo-location-policy/m-p/143531#M72741</guid>
      <dc:creator>nflnetwork29</dc:creator>
      <dc:date>2022-03-11T16:25:13Z</dc:date>
    </item>
    <item>
      <title>Re: possible to filter logs by geo location policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/possible-to-filter-logs-by-geo-location-policy/m-p/143534#M72742</link>
      <description>&lt;P&gt;You can simply use the search field for the specific country your looking for if you're tracking that specific rule.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="tinyMceEditor_bc203f4ced797aCE_SE_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 17:28:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/possible-to-filter-logs-by-geo-location-policy/m-p/143534#M72742</guid>
      <dc:creator>CE_SE</dc:creator>
      <dc:date>2022-03-11T17:28:44Z</dc:date>
    </item>
    <item>
      <title>Re: possible to filter logs by geo location policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/possible-to-filter-logs-by-geo-location-policy/m-p/143537#M72743</link>
      <description>&lt;P&gt;You can do something like this in log search:&lt;/P&gt;
&lt;P&gt;src_country: "Israel"&lt;/P&gt;
&lt;P&gt;You can apply same logic to dst country&lt;/P&gt;
&lt;P&gt;dst_country: "China"&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 18:37:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/possible-to-filter-logs-by-geo-location-policy/m-p/143537#M72743</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-03-11T18:37:34Z</dc:date>
    </item>
    <item>
      <title>Re: possible to filter logs by geo location policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/possible-to-filter-logs-by-geo-location-policy/m-p/143552#M72744</link>
      <description>&lt;P&gt;hmmm not working for me&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 21:15:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/possible-to-filter-logs-by-geo-location-policy/m-p/143552#M72744</guid>
      <dc:creator>nflnetwork29</dc:creator>
      <dc:date>2022-03-11T21:15:56Z</dc:date>
    </item>
    <item>
      <title>Re: possible to filter logs by geo location policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/possible-to-filter-logs-by-geo-location-policy/m-p/143553#M72745</link>
      <description>&lt;P&gt;Not sure what to tell you then...I just did 3 filters on customer's environment and did below:&lt;/P&gt;
&lt;P&gt;src_country: "Canada"&lt;/P&gt;
&lt;P&gt;dst_country: "Canada"&lt;/P&gt;
&lt;P&gt;dst_country: "China"&lt;/P&gt;
&lt;P&gt;All 3 worked fine...can you attach a screenshot?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 21:21:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/possible-to-filter-logs-by-geo-location-policy/m-p/143553#M72745</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-03-11T21:21:06Z</dc:date>
    </item>
    <item>
      <title>Re: possible to filter logs by geo location policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/possible-to-filter-logs-by-geo-location-policy/m-p/143555#M72746</link>
      <description>&lt;P&gt;I agree using the above search method is successful.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 21:26:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/possible-to-filter-logs-by-geo-location-policy/m-p/143555#M72746</guid>
      <dc:creator>CE_SE</dc:creator>
      <dc:date>2022-03-11T21:26:43Z</dc:date>
    </item>
    <item>
      <title>Re: possible to filter logs by geo location policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/possible-to-filter-logs-by-geo-location-policy/m-p/143570#M72747</link>
      <description>&lt;P&gt;Well, works the same way, with or without the quotes : - )&lt;/P&gt;</description>
      <pubDate>Sat, 12 Mar 2022 02:51:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/possible-to-filter-logs-by-geo-location-policy/m-p/143570#M72747</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-03-12T02:51:15Z</dc:date>
    </item>
    <item>
      <title>Re: possible to filter logs by geo location policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/possible-to-filter-logs-by-geo-location-policy/m-p/143578#M72748</link>
      <description>&lt;P&gt;If you're using the new Geo Policy (In Access Control policy) I suggest you filter by rule name.&lt;/P&gt;
&lt;P&gt;If you're not using the new Geo Policy I suggest to move to the new. It's better and future features would be available for it.&lt;/P&gt;
&lt;P&gt;Here's how:&lt;/P&gt;
&lt;P&gt;1) Go to Access Control policy&lt;/P&gt;
&lt;P&gt;2) Add a new rule and in the source/destination you can click on the "+" , Import -&amp;gt; Updateable Objects... (see attached picture).&lt;/P&gt;
&lt;P&gt;3) In the object, search for "GEO Locations", and further select the countries you wish to use in the rule. You can use multiple countries per rule.&lt;/P&gt;
&lt;P&gt;4) Define action and in the track put the desired log level.&lt;/P&gt;
&lt;P&gt;5) Install policy.&lt;/P&gt;</description>
      <pubDate>Sat, 12 Mar 2022 14:15:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/possible-to-filter-logs-by-geo-location-policy/m-p/143578#M72748</guid>
      <dc:creator>Amir_Senn</dc:creator>
      <dc:date>2022-03-12T14:15:33Z</dc:date>
    </item>
    <item>
      <title>Re: possible to filter logs by geo location policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/possible-to-filter-logs-by-geo-location-policy/m-p/194737#M72749</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Given that many people will be using updatable objects rather than the old geo-policy, being unable to search logs directly by country seems to be quite a limitation. The suggestion of adding additional rules to allow filter based on rule UID is not a great workaround for (most) environment where change control is required for a rule.&lt;/P&gt;&lt;P&gt;"I need to add a rule because the product does not permit viewing logs by country"... If it's possible to display the flag in the log view then surely it must be possible to extend this to a search field. This shouldn't need a RFE, it should be included already.&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 00:00:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/possible-to-filter-logs-by-geo-location-policy/m-p/194737#M72749</guid>
      <dc:creator>Paul_Hagyard</dc:creator>
      <dc:date>2023-10-11T00:00:49Z</dc:date>
    </item>
    <item>
      <title>Re: possible to filter logs by geo location policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/possible-to-filter-logs-by-geo-location-policy/m-p/194743#M72750</link>
      <description>&lt;P&gt;You dont need to add any rules to search by country, works fine by using src_country and dst_country filters as examples we gave in the post.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 01:12:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/possible-to-filter-logs-by-geo-location-policy/m-p/194743#M72750</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-11T01:12:30Z</dc:date>
    </item>
    <item>
      <title>Re: possible to filter logs by geo location policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/possible-to-filter-logs-by-geo-location-policy/m-p/194745#M72751</link>
      <description>&lt;P&gt;I'm using R81.20 JHF 26 SC/GW and it's not working. If I filter on src_country:"New Zealand" all I see is my Mobile Access logs - despite there being numerous firewall blade logs from New Zealand sources. I even have NZ as an updatable object in a rule.&lt;/P&gt;&lt;P&gt;Again, the log viewer can show a flag, I shouldn't need to import updatable objects to filter in the log viewer.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 01:39:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/possible-to-filter-logs-by-geo-location-policy/m-p/194745#M72751</guid>
      <dc:creator>Paul_Hagyard</dc:creator>
      <dc:date>2023-10-11T01:39:34Z</dc:date>
    </item>
    <item>
      <title>Re: possible to filter logs by geo location policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/possible-to-filter-logs-by-geo-location-policy/m-p/194746#M72752</link>
      <description>&lt;P&gt;Thats very odd, because I mever had the issue even back in R81.10. I agree with your assesment that you should not need to import updatable object to do the filter. Are you able to send a screenshot of the filter?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 01:43:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/possible-to-filter-logs-by-geo-location-policy/m-p/194746#M72752</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-11T01:43:09Z</dc:date>
    </item>
    <item>
      <title>Re: possible to filter logs by geo location policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/possible-to-filter-logs-by-geo-location-policy/m-p/194896#M72753</link>
      <description>&lt;P&gt;Current logs on the firewall blade showing traffic from Australia:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Log_filter_by_country_1.png" style="width: 929px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22767i9DEC7F94ACD484B0/image-size/large?v=v2&amp;amp;px=999" role="button" title="Log_filter_by_country_1.png" alt="Log_filter_by_country_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Attempt to filter by country shows no logs:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Log_filter_by_country_2.png" style="width: 930px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22768iB6BC54C8BD0B4F01/image-size/large?v=v2&amp;amp;px=999" role="button" title="Log_filter_by_country_2.png" alt="Log_filter_by_country_2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I went for Aussie as it removes the chance of some issue with spaces in the country name. I've tried without the quotes, with single quotes... nada&lt;/P&gt;&lt;P&gt;If I remove the filter on blade and change to src_country:"New Zealand" then I can see my VPN RAS connections from yesterday:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Log_filter_by_country_3.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22769i1AACE04EB40DFBAB/image-size/large?v=v2&amp;amp;px=999" role="button" title="Log_filter_by_country_3.png" alt="Log_filter_by_country_3.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2023 01:29:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/possible-to-filter-logs-by-geo-location-policy/m-p/194896#M72753</guid>
      <dc:creator>Paul_Hagyard</dc:creator>
      <dc:date>2023-10-12T01:29:12Z</dc:date>
    </item>
    <item>
      <title>Re: possible to filter logs by geo location policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/possible-to-filter-logs-by-geo-location-policy/m-p/194897#M72754</link>
      <description>&lt;P&gt;I just found that one of our customers had this issue last year and it was solved by running cloudguard stop and cloudguard start on the mgmt server. Not saying it will work for you, but worth a try. If not, I would maybe reach out to TAC to see what they advise. Also, does not hurt to reboot the mgmt server either, as it does not cause any traffic issues.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2023 01:35:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/possible-to-filter-logs-by-geo-location-policy/m-p/194897#M72754</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-12T01:35:22Z</dc:date>
    </item>
    <item>
      <title>Re: possible to filter logs by geo location policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/possible-to-filter-logs-by-geo-location-policy/m-p/194902#M72755</link>
      <description>&lt;P&gt;That sounds like the service desk: "have you tried turning it off and on again?" &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&amp;nbsp; Does appear to work as often for infrastructure as endpoints...&lt;/P&gt;&lt;P&gt;No change restarting the CloudGuard controller or cpstop/cpstart. TAC request would require having a customer wanting me to spend more of their time on this!&lt;/P&gt;&lt;P&gt;Exporting to CSV from SmartView includes columns src_uo_name and dst_uo_name (source/destination updatable object name"), so if you have the updatable objects defined (and probably active in a rule) you could use SmartView - but hardly convenient. You seemingly can't filter on these columns (src_uo_name etc) in SmartConsole either.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2023 02:31:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/possible-to-filter-logs-by-geo-location-policy/m-p/194902#M72755</guid>
      <dc:creator>Paul_Hagyard</dc:creator>
      <dc:date>2023-10-12T02:31:26Z</dc:date>
    </item>
    <item>
      <title>Re: possible to filter logs by geo location policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/possible-to-filter-logs-by-geo-location-policy/m-p/194903#M72756</link>
      <description>&lt;P&gt;Sorry mate, not sure what else to suggest. I had never had this problem myself, so if those things we discussed did not work, then only other logical options I see are either TAC case or see if someone else on here might have a better suggestions.&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2023 02:39:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/possible-to-filter-logs-by-geo-location-policy/m-p/194903#M72756</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-12T02:39:44Z</dc:date>
    </item>
  </channel>
</rss>

