<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to troubleshoot an app drop with the extended log options in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-troubleshoot-an-app-drop-with-the-extended-log-options/m-p/23990#M98442</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You hit a nail on the head Tomer! It's been bugging me for a while but so far have had no time to dig into it. I noticed that some of our logs started reported sessions after R80.x upgrades even though we never specifically set them. And when i check the rule it's not ticked.&lt;/P&gt;&lt;P&gt;Do you have any more information about how R77.30 to R80.x should have treated this particular option. Also what are CPU impacts of all those options in more detail?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To give you example, this traffic is logged as "session"&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/62176_pastedImage_1.png" style="width: 620px; height: 111px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but the rule is set to "none"!&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/62177_pastedImage_2.png" style="width: 620px; height: 153px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this a SR candidate?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 19 Jan 2018 10:11:51 GMT</pubDate>
    <dc:creator>Kaspars_Zibarts</dc:creator>
    <dc:date>2018-01-19T10:11:51Z</dc:date>
    <item>
      <title>How to troubleshoot an app drop with the extended log options</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-troubleshoot-an-app-drop-with-the-extended-log-options/m-p/23989#M98441</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Let's say you enabled an application, but traffic still gets dropped from some reason.&lt;/P&gt;&lt;P&gt;In the logs, all you see is&amp;nbsp;hits on the any, any, drop rule, but this could come from many different users.&lt;/P&gt;&lt;P&gt;What you can do is to change the default logging setting in the Track column from &lt;STRONG&gt;"Log"&lt;/STRONG&gt; to:&lt;/P&gt;&lt;P&gt;- &lt;STRONG&gt;"Extended Log"&lt;/STRONG&gt;:&amp;nbsp;Adds application info to the logs.&lt;/P&gt;&lt;P&gt;- &lt;STRONG&gt;"Detailed Log"&lt;/STRONG&gt;: Adds resource and file to the logs.&lt;/P&gt;&lt;P&gt;You could also add the option to generate another &lt;STRONG&gt;Log Per Session&lt;/STRONG&gt;, in addition to the usual log per connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please note that each addition to a log gets&amp;nbsp;adds a performance impact. This is why &lt;STRONG&gt;the defaults&lt;/STRONG&gt; for a Track column are relevant to what you picked in a rule: Rules with application objects get the Extended Log by default, while rules with content awareness get the Detailed Log by default.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="62152" alt="" class="image-1 jive-image j-img-original" src="/legacyfs/online/checkpoint/62152_1 initial.png" style="width: 620px; height: 330px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="62156" alt="" class="image-2 jive-image j-img-original" src="/legacyfs/online/checkpoint/62156_2 change the track option.png" style="width: 620px; height: 330px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-5 jive-image j-img-original" src="/legacyfs/online/checkpoint/62159_3 track options.png" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="62158" alt="" class="image-4 jive-image j-img-original" src="/legacyfs/online/checkpoint/62158_4 log per session.png" style="width: 620px; height: 400px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if adding more log details to the highly hit cleanup rule can add performance to the log server, how can we overcome this?&lt;/P&gt;&lt;P&gt;a. You could apply that temporarily until fixing the problem, and then revert to "Log"&lt;/P&gt;&lt;P&gt;b. You could take that source traffic, &lt;STRONG&gt;make that an inline layer&lt;/STRONG&gt;, and in the Drop rule of that inline layer which will probably get hit a lot less than the general policy, change the log setting. Afterwards you can undo the&amp;nbsp;inlining or just keep it segmented as it is.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us know your feedback on this case.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Jan 2018 20:51:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-troubleshoot-an-app-drop-with-the-extended-log-options/m-p/23989#M98441</guid>
      <dc:creator>Tomer_Sole</dc:creator>
      <dc:date>2018-01-18T20:51:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot an app drop with the extended log options</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-troubleshoot-an-app-drop-with-the-extended-log-options/m-p/23990#M98442</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You hit a nail on the head Tomer! It's been bugging me for a while but so far have had no time to dig into it. I noticed that some of our logs started reported sessions after R80.x upgrades even though we never specifically set them. And when i check the rule it's not ticked.&lt;/P&gt;&lt;P&gt;Do you have any more information about how R77.30 to R80.x should have treated this particular option. Also what are CPU impacts of all those options in more detail?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To give you example, this traffic is logged as "session"&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/62176_pastedImage_1.png" style="width: 620px; height: 111px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but the rule is set to "none"!&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/62177_pastedImage_2.png" style="width: 620px; height: 153px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this a SR candidate?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jan 2018 10:11:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-troubleshoot-an-app-drop-with-the-extended-log-options/m-p/23990#M98442</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-01-19T10:11:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot an app drop with the extended log options</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-troubleshoot-an-app-drop-with-the-extended-log-options/m-p/23991#M98443</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Kaspars,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you verify this solution regarding upgrade from R7X to R80.10: &lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk116580" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk116580"&gt;Tracking Objects are missing after upgrade to R80.10 (Track column in Access Policy)&lt;/A&gt; ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jan 2018 13:32:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-troubleshoot-an-app-drop-with-the-extended-log-options/m-p/23991#M98443</guid>
      <dc:creator>KennyManrique</dc:creator>
      <dc:date>2018-01-19T13:32:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot an app drop with the extended log options</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-troubleshoot-an-app-drop-with-the-extended-log-options/m-p/23992#M98444</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe, I've seen same behavior in straight R80.10 implementations as well, not only the upgrades.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jan 2018 14:22:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-troubleshoot-an-app-drop-with-the-extended-log-options/m-p/23992#M98444</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-01-19T14:22:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot an app drop with the extended log options</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-troubleshoot-an-app-drop-with-the-extended-log-options/m-p/23993#M98445</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great - didn't see this SK before!. Bit late now &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&amp;nbsp;And now that I actually spent whole 5mins (instead of whinging..) I found it set on Application layer. So even though we use it as a "plain" firewall, we must have messed around at some point and created this app rule. Or it came as default in R80. Not 100%&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/62426_pastedImage_4.png" style="width: 620px; height: 198px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jan 2018 18:49:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-troubleshoot-an-app-drop-with-the-extended-log-options/m-p/23993#M98445</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-01-19T18:49:01Z</dc:date>
    </item>
  </channel>
</rss>

