<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Spark does not log NATed traffic in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-does-not-log-NATed-traffic/m-p/253348#M12950</link>
    <description>&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;We are using local management with cloud connected features for backups and e&lt;SPAN class=""&gt;xtended monitorin&lt;/SPAN&gt;g. We are using&amp;nbsp;R81.10.17 (996004653)&lt;BR /&gt;&lt;BR /&gt;This is how the NAT rules look like:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Manual NAT rules.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30962i2E8F52D9F81DAB0D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Manual NAT rules.jpg" alt="Manual NAT rules.jpg" /&gt;&lt;/span&gt;This is the corresponding access policy rule:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Access Policy rule.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30963i303E275B8C530750/image-size/large?v=v2&amp;amp;px=999" role="button" title="Access Policy rule.jpg" alt="Access Policy rule.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Traffic is flowing according to rules confirmed with TCPdump. But the related logs are not in the local security logs, nor int the cloud based Quantum Spark Management&lt;BR /&gt;&lt;BR /&gt;In the sever wizard, which we did not use, there is this option:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Wizzard sample.jpg" style="width: 588px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30964iC90A77D38DBA5F6D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Wizzard sample.jpg" alt="Wizzard sample.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;I assume that when creating the rules manually, the "accepted connections" are not logged but I cannot find such an option/checkbox within the manually created rules that could enable this&lt;/P&gt;</description>
    <pubDate>Thu, 17 Jul 2025 07:14:06 GMT</pubDate>
    <dc:creator>Martin_Sykora</dc:creator>
    <dc:date>2025-07-17T07:14:06Z</dc:date>
    <item>
      <title>Spark does not log NATed traffic</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-does-not-log-NATed-traffic/m-p/253299#M12947</link>
      <description>&lt;P&gt;Hi.&lt;BR /&gt;&lt;BR /&gt;On a 1595 cluster I have a manual NAT rule created that forwards Incoming traffic from the Internet that uses a custom port to a an internal IP address running a web service. I have a corresponding rule in access policy. Traffic flow is as expected and the rules does their job. However although the access policy rule is set to log, I do not see any logs of the accepted/NATted traffic.&lt;BR /&gt;&lt;BR /&gt;The NAT and access policy rules have not been created by the server wizard. However by default in the wizard there is an unchecked box for logging accepted connections. It seems to me&amp;nbsp; that this is the functionality I am looking, but I cannot find any checkbox for enabling this when rule is generated manually.&lt;/P&gt;&lt;P&gt;Do you have any idea how to get the logs working with manually created rules?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jul 2025 13:20:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-does-not-log-NATed-traffic/m-p/253299#M12947</guid>
      <dc:creator>Martin_Sykora</dc:creator>
      <dc:date>2025-07-16T13:20:49Z</dc:date>
    </item>
    <item>
      <title>Re: Spark does not log NATed traffic</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-does-not-log-NATed-traffic/m-p/253300#M12948</link>
      <description>&lt;P&gt;Can you share some screenshots? Also, what version? Local or central management?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jul 2025 13:23:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-does-not-log-NATed-traffic/m-p/253300#M12948</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-07-16T13:23:40Z</dc:date>
    </item>
    <item>
      <title>Re: Spark does not log NATed traffic</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-does-not-log-NATed-traffic/m-p/253335#M12949</link>
      <description>&lt;P&gt;Is your Access Policy Control set to Strict?&lt;BR /&gt;This is in Access Policy &amp;gt; Firewall &amp;gt; Blade Control&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2025 00:05:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-does-not-log-NATed-traffic/m-p/253335#M12949</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-07-17T00:05:55Z</dc:date>
    </item>
    <item>
      <title>Re: Spark does not log NATed traffic</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-does-not-log-NATed-traffic/m-p/253348#M12950</link>
      <description>&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;We are using local management with cloud connected features for backups and e&lt;SPAN class=""&gt;xtended monitorin&lt;/SPAN&gt;g. We are using&amp;nbsp;R81.10.17 (996004653)&lt;BR /&gt;&lt;BR /&gt;This is how the NAT rules look like:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Manual NAT rules.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30962i2E8F52D9F81DAB0D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Manual NAT rules.jpg" alt="Manual NAT rules.jpg" /&gt;&lt;/span&gt;This is the corresponding access policy rule:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Access Policy rule.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30963i303E275B8C530750/image-size/large?v=v2&amp;amp;px=999" role="button" title="Access Policy rule.jpg" alt="Access Policy rule.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Traffic is flowing according to rules confirmed with TCPdump. But the related logs are not in the local security logs, nor int the cloud based Quantum Spark Management&lt;BR /&gt;&lt;BR /&gt;In the sever wizard, which we did not use, there is this option:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Wizzard sample.jpg" style="width: 588px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30964iC90A77D38DBA5F6D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Wizzard sample.jpg" alt="Wizzard sample.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;I assume that when creating the rules manually, the "accepted connections" are not logged but I cannot find such an option/checkbox within the manually created rules that could enable this&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2025 07:14:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-does-not-log-NATed-traffic/m-p/253348#M12950</guid>
      <dc:creator>Martin_Sykora</dc:creator>
      <dc:date>2025-07-17T07:14:06Z</dc:date>
    </item>
    <item>
      <title>Re: Spark does not log NATed traffic</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-does-not-log-NATed-traffic/m-p/253349#M12951</link>
      <description>&lt;P&gt;Policy is set to standard with "log all" for both blocked and allowed traffic&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2025 07:15:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-does-not-log-NATed-traffic/m-p/253349#M12951</guid>
      <dc:creator>Martin_Sykora</dc:creator>
      <dc:date>2025-07-17T07:15:02Z</dc:date>
    </item>
    <item>
      <title>Re: Spark does not log NATed traffic</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-does-not-log-NATed-traffic/m-p/253373#M12952</link>
      <description>&lt;P&gt;Servers are not exactly NAT rules&lt;BR /&gt;Can you not go to Users and Objects &amp;gt; Network Resources &amp;gt; Servers and change the definition to log the connections?&lt;BR /&gt;Here’s my configuration for a server object:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IMG_3203.jpeg" style="width: 1170px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30965i6F8345A161FFAE6A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="IMG_3203.jpeg" alt="IMG_3203.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2025 14:03:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-does-not-log-NATed-traffic/m-p/253373#M12952</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-07-17T14:03:30Z</dc:date>
    </item>
    <item>
      <title>Re: Spark does not log NATed traffic</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-does-not-log-NATed-traffic/m-p/253432#M12953</link>
      <description>&lt;P&gt;Well I have tried now to do it both via single IP network objects and and via new server server object (like in your screenshot). Both times the traffic flow worked as expected, But I do not get any logs for the traffic.&lt;/P&gt;&lt;DIV class=""&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="9001 logs missing.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30976i47F6729C018110AB/image-size/large?v=v2&amp;amp;px=999" role="button" title="9001 logs missing.jpg" alt="9001 logs missing.jpg" /&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;P&gt;There should be a bunch of accepted logs with the service 9001 with the same pair of source/destination IP addresses, which was clearly working, but nothing shows up&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jul 2025 12:24:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-does-not-log-NATed-traffic/m-p/253432#M12953</guid>
      <dc:creator>Martin_Sykora</dc:creator>
      <dc:date>2025-07-18T12:24:43Z</dc:date>
    </item>
    <item>
      <title>Re: Spark does not log NATed traffic</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-does-not-log-NATed-traffic/m-p/253677#M12957</link>
      <description>&lt;P&gt;Have you opened a TAC case on this?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jul 2025 13:10:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-does-not-log-NATed-traffic/m-p/253677#M12957</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-07-22T13:10:26Z</dc:date>
    </item>
    <item>
      <title>Re: Spark does not log NATed traffic</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-does-not-log-NATed-traffic/m-p/253746#M12958</link>
      <description>&lt;P&gt;Not yet. I wanted to run this through the community first, just to see if it's not a config error on mi side.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 09:19:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-does-not-log-NATed-traffic/m-p/253746#M12958</guid>
      <dc:creator>Martin_Sykora</dc:creator>
      <dc:date>2025-07-23T09:19:26Z</dc:date>
    </item>
    <item>
      <title>Re: Spark does not log NATed traffic</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-does-not-log-NATed-traffic/m-p/253921#M12971</link>
      <description>&lt;P&gt;I second this question... have multiple custom inbound rules that work as expected. However, do not see any logged inbound traffic. Only rules where inbound TCP port is not redirected to a different port shows logs for outbound traffic. All other inbound rules redirect a custom TCP port to a different port (eg. TCP 1650 on WAN interface to TCP 22 on internal server); none of these rules log any traffic, despite logging enabled. All allowed traffic is logged and all denied traffic is logged.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jul 2025 05:05:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-does-not-log-NATed-traffic/m-p/253921#M12971</guid>
      <dc:creator>Ashley_C</dc:creator>
      <dc:date>2025-07-25T05:05:57Z</dc:date>
    </item>
    <item>
      <title>Re: Spark does not log NATed traffic</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-does-not-log-NATed-traffic/m-p/253964#M12979</link>
      <description>&lt;P&gt;I recommend opening a TAC case if this isn't working as expected.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jul 2025 13:42:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-does-not-log-NATed-traffic/m-p/253964#M12979</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-07-25T13:42:33Z</dc:date>
    </item>
  </channel>
</rss>

