<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: RTP traffic doesn't show in the logs in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/RTP-traffic-doesn-t-show-in-the-logs/m-p/243070#M40641</link>
    <description>&lt;P&gt;What services are you using in your rules to allow the traffic?&lt;/P&gt;</description>
    <pubDate>Wed, 05 Mar 2025 13:48:15 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2025-03-05T13:48:15Z</dc:date>
    <item>
      <title>RTP traffic doesn't show in the logs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/RTP-traffic-doesn-t-show-in-the-logs/m-p/243017#M40630</link>
      <description>&lt;P&gt;Hi people,&lt;/P&gt;&lt;P&gt;We have a CCTV system in the company and I'm analysing this communication in the checkpoint, but I can't see any RTP packets flowing through the gateways. I can see the RTSP (control packets) traffic when the camera is initializing but can't see subsequent RTP traffic (the real stream) coming afterwards. I already checked the specific rule for this traffic, and it set to log it, however I can only see this traffic on Wireshark capturing in the local machine. I'm assuming the traffic like this (stream) is not logged by default, as it doesn't make sense to log every packet of stream for every camera.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rtp_packes.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29794iA061B1983E0B9B98/image-size/large?v=v2&amp;amp;px=999" role="button" title="rtp_packes.png" alt="rtp_packes.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Is there any hidden option to enable this log? maybe something specific for UDP/stream?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2025 00:13:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/RTP-traffic-doesn-t-show-in-the-logs/m-p/243017#M40630</guid>
      <dc:creator>trsantos</dc:creator>
      <dc:date>2025-03-05T00:13:29Z</dc:date>
    </item>
    <item>
      <title>Re: RTP traffic doesn't show in the logs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/RTP-traffic-doesn-t-show-in-the-logs/m-p/243070#M40641</link>
      <description>&lt;P&gt;What services are you using in your rules to allow the traffic?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2025 13:48:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/RTP-traffic-doesn-t-show-in-the-logs/m-p/243070#M40641</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-03-05T13:48:15Z</dc:date>
    </item>
    <item>
      <title>Re: RTP traffic doesn't show in the logs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/RTP-traffic-doesn-t-show-in-the-logs/m-p/243139#M40656</link>
      <description>&lt;P&gt;We are using "Any" for this particular traffic, and I can only see this rule logging rtsp on tcp/554, although I can see the higher ports (50004 on this specific case, it uses dynamic ports) via fw monitor.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fw_rtsp.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29828i578E4FCAFF6B98F6/image-size/large?v=v2&amp;amp;px=999" role="button" title="fw_rtsp.png" alt="fw_rtsp.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2025 04:06:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/RTP-traffic-doesn-t-show-in-the-logs/m-p/243139#M40656</guid>
      <dc:creator>trsantos</dc:creator>
      <dc:date>2025-03-06T04:06:32Z</dc:date>
    </item>
    <item>
      <title>Re: RTP traffic doesn't show in the logs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/RTP-traffic-doesn-t-show-in-the-logs/m-p/243214#M40667</link>
      <description>&lt;P&gt;RTSP is a "Match for Any" service, which is why it's being used.&lt;BR /&gt;I assume it is not logging the data stream by design, but TAC would have to to confirm.&lt;/P&gt;
&lt;P&gt;Not sure there's an option in this service to enable logging the data stream, but you can disable this service (and handler) from being matched by opening up the service and unchecking the "match for any" option.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29846i7228FF6DABA4FD36/image-size/medium?v=v2&amp;amp;px=400" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2025 00:09:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/RTP-traffic-doesn-t-show-in-the-logs/m-p/243214#M40667</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-03-07T00:09:40Z</dc:date>
    </item>
  </channel>
</rss>

