<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: no SIP Logs in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/no-SIP-Logs/m-p/98959#M78145</link>
    <description>&lt;P&gt;Contact TAC - if you see connections in TCP dump that do not show in logs that is an issue !&lt;/P&gt;</description>
    <pubDate>Tue, 13 Oct 2020 11:48:33 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2020-10-13T11:48:33Z</dc:date>
    <item>
      <title>no SIP Logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/no-SIP-Logs/m-p/98940#M78140</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello Community, &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have something very strange here on the Firewall Gateway R80.30. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The customer has configured communication between a server and voice system via the SIP port UDP 5060. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This communication is not logged, however, I did not find any entries in the logs. But I can see exactly via TCP Dump that this communication is present on the interfaces. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I also have all the rules on logging in the policy, I checked this separately. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;As a service I created a new UDP service and only set port 5060. Has anyone seen or had anything like this?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;best regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Nikolai&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 07:31:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/no-SIP-Logs/m-p/98940#M78140</guid>
      <dc:creator>Nikolai_Borhart</dc:creator>
      <dc:date>2020-10-13T07:31:44Z</dc:date>
    </item>
    <item>
      <title>Re: no SIP Logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/no-SIP-Logs/m-p/98943#M78141</link>
      <description>&lt;P&gt;maybe dropped ? Try zdebug drop...&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 07:41:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/no-SIP-Logs/m-p/98943#M78141</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-10-13T07:41:05Z</dc:date>
    </item>
    <item>
      <title>Re: no SIP Logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/no-SIP-Logs/m-p/98948#M78142</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I made fw ctl zdebug drop on the firewall gateway and I have no entries for this communication in it.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;But via TCP Dump I see this communication coming in at the inbound interface and out at the outbound interface.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 08:11:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/no-SIP-Logs/m-p/98948#M78142</guid>
      <dc:creator>Nikolai_Borhart</dc:creator>
      <dc:date>2020-10-13T08:11:48Z</dc:date>
    </item>
    <item>
      <title>Re: no SIP Logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/no-SIP-Logs/m-p/98949#M78143</link>
      <description>&lt;P&gt;Log implicit rules ?&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 08:14:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/no-SIP-Logs/m-p/98949#M78143</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-10-13T08:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: no SIP Logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/no-SIP-Logs/m-p/98950#M78144</link>
      <description>&lt;P&gt;Log Imlied Rules is activated under Global Properties-&amp;gt; Firewall.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 08:21:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/no-SIP-Logs/m-p/98950#M78144</guid>
      <dc:creator>Nikolai_Borhart</dc:creator>
      <dc:date>2020-10-13T08:21:28Z</dc:date>
    </item>
    <item>
      <title>Re: no SIP Logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/no-SIP-Logs/m-p/98959#M78145</link>
      <description>&lt;P&gt;Contact TAC - if you see connections in TCP dump that do not show in logs that is an issue !&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 11:48:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/no-SIP-Logs/m-p/98959#M78145</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-10-13T11:48:33Z</dc:date>
    </item>
    <item>
      <title>Re: no SIP Logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/no-SIP-Logs/m-p/162962#M78146</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/22895"&gt;@Nikolai_Borhart&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Did you find a solution to this issue ? I've the same exact problem.&lt;/P&gt;&lt;P&gt;Thanks !&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 16:26:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/no-SIP-Logs/m-p/162962#M78146</guid>
      <dc:creator>Leader_Kiongi</dc:creator>
      <dc:date>2022-11-23T16:26:40Z</dc:date>
    </item>
  </channel>
</rss>

