<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Return traffic in checkpoint in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Return-traffic-in-checkpoint/m-p/84266#M80341</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;We would like to know&amp;nbsp;if we can have the see return traffic entries in the logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As we aware once we have the connection matches the policy, it logs the traffic and been written in the connection table.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And the return traffic matches the existing connection table entry and been allowed / dropped. And we cannot see the return traffic logs in the checkpoint.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Apart from TCPDUMP, do we have any way to find the historical return traffic logs ?&lt;BR /&gt;2) If secureXL is disabled, can we see the return traffic logs ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vengatesh SR&lt;/P&gt;</description>
    <pubDate>Tue, 05 May 2020 20:06:04 GMT</pubDate>
    <dc:creator>Vengatesh-SR</dc:creator>
    <dc:date>2020-05-05T20:06:04Z</dc:date>
    <item>
      <title>Return traffic in checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Return-traffic-in-checkpoint/m-p/84266#M80341</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;We would like to know&amp;nbsp;if we can have the see return traffic entries in the logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As we aware once we have the connection matches the policy, it logs the traffic and been written in the connection table.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And the return traffic matches the existing connection table entry and been allowed / dropped. And we cannot see the return traffic logs in the checkpoint.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Apart from TCPDUMP, do we have any way to find the historical return traffic logs ?&lt;BR /&gt;2) If secureXL is disabled, can we see the return traffic logs ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vengatesh SR&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2020 20:06:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Return-traffic-in-checkpoint/m-p/84266#M80341</guid>
      <dc:creator>Vengatesh-SR</dc:creator>
      <dc:date>2020-05-05T20:06:04Z</dc:date>
    </item>
    <item>
      <title>Re: Return traffic in checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Return-traffic-in-checkpoint/m-p/84272#M80342</link>
      <description>&lt;P&gt;The closest you can get is to enable "Accounting" in the Track field along with "Log" to get this information.&amp;nbsp; Every 10 minutes or when the connection ends (whichever comes first), additional information is added to the log entry including firewall egress interface, connection time, and bytes/sent and received.&amp;nbsp; If these values are nonzero two-way connectivity is working.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Modifying the state of SecureXL won't change this, but if you want to use &lt;STRONG&gt;fw monitor&lt;/STRONG&gt; to capture accelerated traffic in R80.20+ check out the &lt;STRONG&gt;-F 0,0,0,0,0&lt;/STRONG&gt; filtering syntax for &lt;STRONG&gt;fw monitor&lt;/STRONG&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2020 21:03:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Return-traffic-in-checkpoint/m-p/84272#M80342</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-05-05T21:03:35Z</dc:date>
    </item>
    <item>
      <title>Re: Return traffic in checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Return-traffic-in-checkpoint/m-p/84281#M80343</link>
      <description>&lt;P&gt;Hi Timothy,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for quick reply.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The reason of this requirement is to randomly check if return traffic flow was complete or not for the existing connections.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can we enable the accounting on all the policies in rulebase in production network ? Is it cause any impact ?&lt;/P&gt;&lt;P&gt;Apart from accounting do we have any other way to view the historical data for the return traffic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vengatesh SR&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2020 22:16:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Return-traffic-in-checkpoint/m-p/84281#M80343</guid>
      <dc:creator>Nagesh_Aithal</dc:creator>
      <dc:date>2020-05-05T22:16:44Z</dc:date>
    </item>
    <item>
      <title>Re: Return traffic in checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Return-traffic-in-checkpoint/m-p/84290#M80344</link>
      <description>&lt;P&gt;A Track of "Log" only tells you what happened when the first packet of the connection was received, unless the log was added on to later by another blade like APCL.&amp;nbsp; Enabling Accounting will cause some additional memory and especially logging overhead on the gateway.&amp;nbsp; I'd try enabling it for a few rules in your policy and assess the impact; if your SMS/Log Server is already somewhat overwhelmed by regular logs, setting Accounting will certainly not help.&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2020 03:20:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Return-traffic-in-checkpoint/m-p/84290#M80344</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-05-06T03:20:45Z</dc:date>
    </item>
  </channel>
</rss>

