<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: viewing LOG - filter on NAT rule # in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/viewing-LOG-filter-on-NAT-rule/m-p/22761#M95650</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is a management/logging feature, the version of gateway is not that relevant.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 27 Jun 2018 15:25:40 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-06-27T15:25:40Z</dc:date>
    <item>
      <title>viewing LOG - filter on NAT rule #</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/viewing-LOG-filter-on-NAT-rule/m-p/22750#M95639</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm using the Logs &amp;amp; Monitor of Domain Management Server ( R80.10 ) on a VS ( R77.30 ).&lt;/P&gt;&lt;P&gt;I'm looking for the field name of&amp;nbsp;"Xlate (NAT) Source IP"&amp;nbsp; to use in the query in Logs &amp;amp; Monitor.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(Already tried filtering using the "Copy Rule UID" of the NAT rule and using it with fieldname rule_uid. )&lt;/P&gt;&lt;P&gt;The drop down list of "other fields"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope there's a complete list of field names somewhere.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Gerard van Leeuwen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2018 13:00:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/viewing-LOG-filter-on-NAT-rule/m-p/22750#M95639</guid>
      <dc:creator>Gerard_van_Lee1</dc:creator>
      <dc:date>2018-05-09T13:00:26Z</dc:date>
    </item>
    <item>
      <title>Re: viewing LOG - filter on NAT rule #</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/viewing-LOG-filter-on-NAT-rule/m-p/22751#M95640</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;While on the logs page, you can right click the grey columns header and then select 'Edit Profile'. From there you can search for various columns to add, search for Xlate and you should find what you are looking for. Trying to add screenshots but having trouble. &lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://community.checkpoint.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2018 13:17:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/viewing-LOG-filter-on-NAT-rule/m-p/22751#M95640</guid>
      <dc:creator>Joshua_Hatter</dc:creator>
      <dc:date>2018-05-09T13:17:17Z</dc:date>
    </item>
    <item>
      <title>Re: viewing LOG - filter on NAT rule #</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/viewing-LOG-filter-on-NAT-rule/m-p/22752#M95641</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I already did add the columns Xlate*. That works well.&lt;/P&gt;&lt;P&gt;But I like to use it as a filter.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2018 13:20:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/viewing-LOG-filter-on-NAT-rule/m-p/22752#M95641</guid>
      <dc:creator>Gerard_van_Lee1</dc:creator>
      <dc:date>2018-05-09T13:20:56Z</dc:date>
    </item>
    <item>
      <title>Re: viewing LOG - filter on NAT rule #</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/viewing-LOG-filter-on-NAT-rule/m-p/22753#M95642</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Typically you can click on the column headers and add filter from there. The option is grayed out for me so I think it is a bad sign. I've asked some other resources, maybe &lt;A href="https://community.checkpoint.com/migrated-users/6703"&gt;Tomer Sole&lt;/A&gt;‌ can have a suggestion.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2018 13:27:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/viewing-LOG-filter-on-NAT-rule/m-p/22753#M95642</guid>
      <dc:creator>Joshua_Hatter</dc:creator>
      <dc:date>2018-05-09T13:27:24Z</dc:date>
    </item>
    <item>
      <title>Re: viewing LOG - filter on NAT rule #</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/viewing-LOG-filter-on-NAT-rule/m-p/22754#M95643</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Where could we see indexed fields &lt;A href="https://community.checkpoint.com/migrated-users/41895"&gt;Joshua Hatter&lt;/A&gt; ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2018 13:33:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/viewing-LOG-filter-on-NAT-rule/m-p/22754#M95643</guid>
      <dc:creator>XavierBens</dc:creator>
      <dc:date>2018-05-09T13:33:51Z</dc:date>
    </item>
    <item>
      <title>Re: viewing LOG - filter on NAT rule #</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/viewing-LOG-filter-on-NAT-rule/m-p/22755#M95644</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Outside the API my management expertise is limited. My best guess is anything in the "Add a search field:" section once you click in the filter bar. Hoping Tomer or someone else can add some feedback. &lt;A href="https://community.checkpoint.com/migrated-users/41594"&gt;Russell Seifert&lt;/A&gt;‌&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2018 14:15:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/viewing-LOG-filter-on-NAT-rule/m-p/22755#M95644</guid>
      <dc:creator>Joshua_Hatter</dc:creator>
      <dc:date>2018-05-09T14:15:37Z</dc:date>
    </item>
    <item>
      <title>Re: viewing LOG - filter on NAT rule #</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/viewing-LOG-filter-on-NAT-rule/m-p/22756#M95645</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;xlatesrc = Xlate (NAT) Source IP&lt;BR /&gt;xlatedst =&amp;nbsp;&lt;SPAN&gt;Xlate (NAT) Destination IP&lt;/SPAN&gt;&lt;BR /&gt;xlatesport =&amp;nbsp;&lt;SPAN&gt;Xlate (NAT) Source Port&lt;/SPAN&gt;&lt;BR /&gt;xlatedport =&amp;nbsp;&lt;SPAN&gt;Xlate (NAT) Destination Port&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Example in filter:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;xlatesport:33028&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;xlatedst:10.1.0.0&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2018 15:25:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/viewing-LOG-filter-on-NAT-rule/m-p/22756#M95645</guid>
      <dc:creator>Russell_Seifert</dc:creator>
      <dc:date>2018-05-09T15:25:06Z</dc:date>
    </item>
    <item>
      <title>Re: viewing LOG - filter on NAT rule #</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/viewing-LOG-filter-on-NAT-rule/m-p/22757#M95646</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Only available starting R80* ?&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/65453_pastedImage_4.png" /&gt;&lt;/P&gt;&lt;P&gt;(on R77.30 SmartLog)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2018 15:35:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/viewing-LOG-filter-on-NAT-rule/m-p/22757#M95646</guid>
      <dc:creator>XavierBens</dc:creator>
      <dc:date>2018-05-09T15:35:06Z</dc:date>
    </item>
    <item>
      <title>Re: viewing LOG - filter on NAT rule #</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/viewing-LOG-filter-on-NAT-rule/m-p/22758#M95647</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct. The NAT fields were not indexed to be searchable on R77.30 and lower due to performance reasons.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2018 18:16:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/viewing-LOG-filter-on-NAT-rule/m-p/22758#M95647</guid>
      <dc:creator>Russell_Seifert</dc:creator>
      <dc:date>2018-05-09T18:16:35Z</dc:date>
    </item>
    <item>
      <title>Re: viewing LOG - filter on NAT rule #</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/viewing-LOG-filter-on-NAT-rule/m-p/22759#M95648</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm sorry Russell. xlatesrc:172.20.0.4 does not work and I'm 100% sure there's such traffic.&lt;/P&gt;&lt;P&gt;I'm aiming the filter for NAT rule number.&lt;/P&gt;&lt;P&gt;The gateways are R77.30 now. Ok I have to wait for this option until those are updated.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2018 18:16:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/viewing-LOG-filter-on-NAT-rule/m-p/22759#M95648</guid>
      <dc:creator>Gerard_van_Lee1</dc:creator>
      <dc:date>2018-05-09T18:16:55Z</dc:date>
    </item>
    <item>
      <title>Re: viewing LOG - filter on NAT rule #</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/viewing-LOG-filter-on-NAT-rule/m-p/22760#M95649</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;I am running R80.10 SMS and R77.30 Gateways (Both running latest Jumbo's). I am also having same issue: Added xlate src IP field to my columns by editing the profile but searching xlatesrc: public IP does not work. But, just entering the public IP in the search without any filters does seem to work at times but not all times.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, my GW's must be on R80+ for this xlate based indexing to work or is it just the SMS needs to be on R80+ ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2018 14:16:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/viewing-LOG-filter-on-NAT-rule/m-p/22760#M95649</guid>
      <dc:creator>venkata_marutur</dc:creator>
      <dc:date>2018-06-27T14:16:56Z</dc:date>
    </item>
    <item>
      <title>Re: viewing LOG - filter on NAT rule #</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/viewing-LOG-filter-on-NAT-rule/m-p/22761#M95650</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is a management/logging feature, the version of gateway is not that relevant.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2018 15:25:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/viewing-LOG-filter-on-NAT-rule/m-p/22761#M95650</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-06-27T15:25:40Z</dc:date>
    </item>
    <item>
      <title>Re: viewing LOG - filter on NAT rule #</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/viewing-LOG-filter-on-NAT-rule/m-p/22762#M95651</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So, any thoughts on why the issue still exists in R80+ SMS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps other users as well.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2018 15:38:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/viewing-LOG-filter-on-NAT-rule/m-p/22762#M95651</guid>
      <dc:creator>venkata_marutur</dc:creator>
      <dc:date>2018-06-27T15:38:57Z</dc:date>
    </item>
    <item>
      <title>Re: viewing LOG - filter on NAT rule #</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/viewing-LOG-filter-on-NAT-rule/m-p/22763#M95652</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sounds like an indexing issue, in which case it's probably worth opening a ticket with the TAC to investigate.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2018 15:55:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/viewing-LOG-filter-on-NAT-rule/m-p/22763#M95652</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-06-27T15:55:12Z</dc:date>
    </item>
    <item>
      <title>Re: viewing LOG - filter on NAT rule #</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/viewing-LOG-filter-on-NAT-rule/m-p/22764#M95653</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Has anyone figured out how to filter SmartLog for NAT Rule Number?&amp;nbsp; When filtering for Access Rule Number it uses "rule:" in the query syntax.&amp;nbsp; However for NAT Rule Number it uses just the rule number in the query syntax which returns no results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are able to filter from Smartview Tracker though....&amp;nbsp;&amp;nbsp; This is on R80.10 management.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Oct 2018 15:47:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/viewing-LOG-filter-on-NAT-rule/m-p/22764#M95653</guid>
      <dc:creator>Raj_Khatri</dc:creator>
      <dc:date>2018-10-11T15:47:50Z</dc:date>
    </item>
    <item>
      <title>Re: viewing LOG - filter on NAT rule #</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/viewing-LOG-filter-on-NAT-rule/m-p/22765#M95654</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So after working with TAC, it appears that the NAT Rule Numbers are not indexed.&amp;nbsp; The only workaround is to open an individual log file and use the following query -&amp;nbsp;&lt;SPAN style="font-size: 11.0pt;"&gt;nat_rulenum: 123&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An RFE has been submitted for this request.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Oct 2018 19:30:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/viewing-LOG-filter-on-NAT-rule/m-p/22765#M95654</guid>
      <dc:creator>Raj_Khatri</dc:creator>
      <dc:date>2018-10-18T19:30:59Z</dc:date>
    </item>
    <item>
      <title>Re: viewing LOG - filter on NAT rule #</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/viewing-LOG-filter-on-NAT-rule/m-p/187874#M95655</link>
      <description>&lt;P&gt;This still seems to be a problem on R81.10.&amp;nbsp; I can't figure out a way to apply a filter on the NAT IP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hide tons of traffic behind my LAN interface IP 192.168.1.1.&amp;nbsp; &amp;nbsp;And of course behind the public interface IP for web access.&lt;/P&gt;&lt;P&gt;If I try&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;xlatesrc:192.168.1.1&lt;/STRONG&gt;&amp;nbsp; I get zero hits.&amp;nbsp; Same if I use the public hide IP.&lt;/P&gt;&lt;P&gt;If I filter on just&amp;nbsp; &amp;nbsp;&lt;STRONG&gt;192.168.1.1&lt;/STRONG&gt;&amp;nbsp; then I get millions of hits for all sorts besides just the NAT.&amp;nbsp; So it's useless.&lt;/P&gt;&lt;P&gt;There must be a way to filter logs on the NAT fields?&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":face_with_rolling_eyes:"&gt;🙄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 13:54:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/viewing-LOG-filter-on-NAT-rule/m-p/187874#M95655</guid>
      <dc:creator>biskit</dc:creator>
      <dc:date>2023-07-27T13:54:28Z</dc:date>
    </item>
  </channel>
</rss>

