<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SMB HTTPS logging &amp;amp; other issues in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175588#M8553</link>
    <description>&lt;P&gt;As an example for OpenVPN (UDP/1194) I would only expect to see an entry for the start of the long lived connection/session. Are you not seeing this or are you expecting something more here?&lt;/P&gt;</description>
    <pubDate>Tue, 21 Mar 2023 14:33:57 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2023-03-21T14:33:57Z</dc:date>
    <item>
      <title>SMB HTTPS logging &amp; other issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175259#M8521</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm seeing some very odd (to me) behaviour with a locally-managed 1450 appliance. I've just re-flashed it using the USB method so that it has a clean install of&amp;nbsp;&lt;STRONG&gt;R77.20.87 (990173120).&lt;/STRONG&gt; Although I did re-import my config after.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To begin with, I see no HTTPS logs whatsoever in the Security log. All my blades/rules have all logging enabled. I even turned on implied rule logging for a time to see if it helped but it didn't really. I saw a bunch more DNS requests and my WebUI activity.&amp;nbsp;&lt;/P&gt;&lt;P&gt;For me to see any HTTPS logs I put a rule at the top of the rulebase disabling all access for the specific host, and then I see some generic HTTPS info at least.&lt;/P&gt;&lt;P&gt;For a long time now, even when HTTPS logs were working, I never get any category or URL information. Is "HTTPS Categorization" mode supposed to be able to do anything these days? I know there are SK articles about CA fixes, etc., but I wasn't sure if they would fix my issues.&lt;/P&gt;&lt;P&gt;I've dabbled with enabling SSL inspection but it doesn't suit my purposes right now.&lt;/P&gt;&lt;P&gt;There definitely seems to be an issue with my HTTPS and especially it's logging.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 21:40:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175259#M8521</guid>
      <dc:creator>n7564773</dc:creator>
      <dc:date>2023-03-17T21:40:28Z</dc:date>
    </item>
    <item>
      <title>Re: SMB HTTPS logging &amp; other issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175260#M8522</link>
      <description>&lt;P&gt;I don't see any VPN traffic either, until it's dropped traffic using the rule I mentioned above. I don't see any allowed Wireguard or OVPN traffic. But I see all of the dropped attempts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have licenses for all of the blades, active until 2024, if that matters.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks...&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 22:15:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175260#M8522</guid>
      <dc:creator>n7564773</dc:creator>
      <dc:date>2023-03-17T22:15:35Z</dc:date>
    </item>
    <item>
      <title>Re: SMB HTTPS logging &amp; other issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175262#M8523</link>
      <description>&lt;P&gt;Your only option on the 1450 is to enable HTTPS Inspection.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTTPS Categorization in R77.20 uses the CN of the certificate to categorize websites.&lt;BR /&gt;R77.20 does not support SNI-based categorization that is available in newer SMB appliances running R80.20.x or R81.10.x.&lt;BR /&gt;1400 Series Appliances are End of Engineering Support, meaning no further software updates are planned aside from bugfixes.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 23:11:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175262#M8523</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-03-17T23:11:06Z</dc:date>
    </item>
    <item>
      <title>Re: SMB HTTPS logging &amp; other issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175266#M8524</link>
      <description>&lt;P&gt;That makes sense, but what about the other logging behaviour? I don't see any VPN traffic whatsoever, not even encrypted packets crossing. I only see details of these packets when I put a rule at the top of the rulebase denying the traffic.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 23:29:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175266#M8524</guid>
      <dc:creator>n7564773</dc:creator>
      <dc:date>2023-03-17T23:29:58Z</dc:date>
    </item>
    <item>
      <title>Re: SMB HTTPS logging &amp; other issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175276#M8525</link>
      <description>&lt;P&gt;What is this setting?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20140i04F2EE79A9761B48/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;And, also (on the same screen):&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="image.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20141i831B78312F470420/image-size/medium?v=v2&amp;amp;px=400" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;Note this is from 1590 running R81.10.xx but I believe R77.20.xx has the same settings.&lt;/P&gt;</description>
      <pubDate>Sat, 18 Mar 2023 00:55:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175276#M8525</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-03-18T00:55:48Z</dc:date>
    </item>
    <item>
      <title>Re: SMB HTTPS logging &amp; other issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175279#M8526</link>
      <description>&lt;P&gt;Is all the logging enabled as per screenshot&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;sent?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 18 Mar 2023 02:27:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175279#M8526</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-18T02:27:20Z</dc:date>
    </item>
    <item>
      <title>Re: SMB HTTPS logging &amp; other issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175280#M8527</link>
      <description>&lt;P&gt;Note for reference a newer R77.20.87 build 990173127 is available for 700 / 1400 appliances (per sk176148 contact Check Point Support to get it).&lt;/P&gt;</description>
      <pubDate>Sat, 18 Mar 2023 02:38:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175280#M8527</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-03-18T02:38:31Z</dc:date>
    </item>
    <item>
      <title>Re: SMB HTTPS logging &amp; other issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175281#M8528</link>
      <description>&lt;P&gt;Good advice, that can only help!&lt;/P&gt;</description>
      <pubDate>Sat, 18 Mar 2023 03:06:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175281#M8528</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-18T03:06:42Z</dc:date>
    </item>
    <item>
      <title>Re: SMB HTTPS logging &amp; other issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175299#M8529</link>
      <description>&lt;P&gt;Thanks. Looks like a lot of good fixes in that, specifically for HTTPS. My certs expired and so I don't have access to open a request to get it anymore, so I'll have to sort something out.&lt;/P&gt;</description>
      <pubDate>Sat, 18 Mar 2023 16:03:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175299#M8529</guid>
      <dc:creator>n7564773</dc:creator>
      <dc:date>2023-03-18T16:03:57Z</dc:date>
    </item>
    <item>
      <title>Re: SMB HTTPS logging &amp; other issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175300#M8530</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes I have all of the expected logging settings enabled, which is why this is so perplexing. Anywhere a log can be enabled, it is.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe it's an issue with how I have service/application groups nested in the rules. I'll try separating them out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Nathan&lt;/P&gt;</description>
      <pubDate>Sat, 18 Mar 2023 16:05:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175300#M8530</guid>
      <dc:creator>n7564773</dc:creator>
      <dc:date>2023-03-18T16:05:12Z</dc:date>
    </item>
    <item>
      <title>Re: SMB HTTPS logging &amp; other issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175439#M8539</link>
      <description>&lt;P&gt;I was able to get the mentioned fix installed. Doesn't appear to be any fix for my logging issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am I not supposed to see logs for encrypted traffic? I realize I won't see what's inside, but shouldn't I still see reference that encrypted data is traversing my interfaces? I see it in packet captures.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2023 16:10:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175439#M8539</guid>
      <dc:creator>n7564773</dc:creator>
      <dc:date>2023-03-20T16:10:25Z</dc:date>
    </item>
    <item>
      <title>Re: SMB HTTPS logging &amp; other issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175443#M8540</link>
      <description>&lt;P&gt;Im fairly positive you should be able to see it. Do you not see any of those at all? Did it ever work?&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2023 16:16:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175443#M8540</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-20T16:16:21Z</dc:date>
    </item>
    <item>
      <title>Re: SMB HTTPS logging &amp; other issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175444#M8541</link>
      <description>&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp; posted: Your only option on the 1450 is to enable HTTPS Inspection.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2023 16:18:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175444#M8541</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-03-20T16:18:04Z</dc:date>
    </item>
    <item>
      <title>Re: SMB HTTPS logging &amp; other issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175448#M8542</link>
      <description>&lt;P&gt;To re-clarify: I'm talking about all encrypted traffic. I don't see any logs whatsoever showing VPN encrypted traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2023 16:20:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175448#M8542</guid>
      <dc:creator>n7564773</dc:creator>
      <dc:date>2023-03-20T16:20:46Z</dc:date>
    </item>
    <item>
      <title>Re: SMB HTTPS logging &amp; other issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175449#M8543</link>
      <description>&lt;P&gt;Just my personal opinion, but I could be mistaken, though, I dont see logically why you would need https inspection on for this to work. I dealt with God knows how many clients who did NOT have inspection on their firewall and this worked without any issues.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2023 16:23:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175449#M8543</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-20T16:23:02Z</dc:date>
    </item>
    <item>
      <title>Re: SMB HTTPS logging &amp; other issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175535#M8547</link>
      <description>&lt;P&gt;Further to&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;earlier post you have your policy/rules set to log in the following section correct?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN log.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20166i7FC596F0B8018366/image-size/large?v=v2&amp;amp;px=999" role="button" title="VPN log.png" alt="VPN log.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2023 04:21:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175535#M8547</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-03-21T04:21:48Z</dc:date>
    </item>
    <item>
      <title>Re: SMB HTTPS logging &amp; other issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175571#M8552</link>
      <description>&lt;P&gt;Correct. All rules are set to log. Implied rule logging is enabled. Global "log all" settings are set to YES. It's as if as soon as any encrypted traffic his an 'allow' rule, logging goes away for that connection. If I put a 'deny' rule for any of this traffic, I start seeing logs again.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2023 13:11:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175571#M8552</guid>
      <dc:creator>n7564773</dc:creator>
      <dc:date>2023-03-21T13:11:41Z</dc:date>
    </item>
    <item>
      <title>Re: SMB HTTPS logging &amp; other issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175588#M8553</link>
      <description>&lt;P&gt;As an example for OpenVPN (UDP/1194) I would only expect to see an entry for the start of the long lived connection/session. Are you not seeing this or are you expecting something more here?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2023 14:33:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175588#M8553</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-03-21T14:33:57Z</dc:date>
    </item>
    <item>
      <title>Re: SMB HTTPS logging &amp; other issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175592#M8554</link>
      <description>&lt;P&gt;I know, for example, on Fortigates, you have an option like below, but Im fairly positive that is not there on SMB appliances (I dont have access to one to confirm):&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20178iA259B6922EDC5B22/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2023 15:07:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175592#M8554</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-21T15:07:41Z</dc:date>
    </item>
    <item>
      <title>Re: SMB HTTPS logging &amp; other issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175593#M8555</link>
      <description>&lt;P&gt;Hi Chris,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't see any reference to the connection whatsoever. Someone unfamiliar with my environment would have no idea the connection was even taking place. I don't want to add more confusion to this discussion, but I think there is a bigger issue with my logging. Many other small things don't get log entries either, but the biggest issue is the encrypted traffic. I thought maybe I messed with some CLI global settings, which is why I factory reset the device with a new image on USB, but that didn't seem to help.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2023 14:57:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-HTTPS-logging-amp-other-issues/m-p/175593#M8555</guid>
      <dc:creator>n7564773</dc:creator>
      <dc:date>2023-03-21T14:57:39Z</dc:date>
    </item>
  </channel>
</rss>

