- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
When the Agents Attack
A Live Look at Agentic Exposure Validation
Bridge the CAASM Gap
with Exposure Management
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Hey guys,
I hope someone might be able to shed some light about this. So, while back, I set up a lab with base R81, mgmt server + 2 single gateways and all works fine, no issues. I upgraded all to R81.10 and still going strong : -).
Now, the other week, to demonstrate R81.10 from scratch to a customer, I built brand new R81.10 (mgmt server + HA cluster) and all seems fine, except I see some odd issues with logging. For example, if I refresh the logs in dashboard, looks okay, but...say if I ping 8.8.8.8 from either cluster member, I can never see any logs, which is not the case in my other lab (works fine). I followed support sk's for this, rebooted many times, did fw logswitch, literally all the steps and still no luck.
I am totally at a loss why this would be happening, makes no logical sense to me.
If anyone can provide some suggestions, I would appreciate it. Anyway, its nothing urgent, since its a lab, but its really puzzling to me why its not working.
tx as always!!
Outbound traffic from the gateway is almost always handled through an implied rule that doesn't log, last I checked...
Outbound traffic from the gateway is almost always handled through an implied rule that doesn't log, last I checked...
Thanks @PhoneBoy . That makes sense, but then how come I see the log via right policy in my other lab?
Not sure, maybe the implied rules were changed?
Or perhaps there is a code changes that impacts this behavior somehow?
I hope you enable log in the rule that allows the traffic, my thought !
I know even after 15 years it would be easy to forget, but it was enabled ;). I think @PhoneBoy is correct.
Definitely no change in implied rules.
Make sure the date and time are correctly configured on gateway and management (log server). You might see logs with huge delays while the date is not correct on one of devices. Best to use NTP to avoid issue.
Thanks @JozkoMrkvicka , but that was not the issue, it was the first thing I checked actually. @PhoneBoy was 100% correct as usual...no offense to anyone else, but he is after all CP master/guru/legend/expert...whatever you want to call it :). I enabled to log implied rules and sure enough, it started to show logs to google dns right away. Funny enough, that option was NOT enabled in R81 and logs were showing actual rule number.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 34 | |
| 22 | |
| 9 | |
| 9 | |
| 7 | |
| 7 | |
| 7 | |
| 5 | |
| 5 | |
| 4 |
Thu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeThu 04 Jun 2026 @ 07:00 PM (IDT)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - AmericaThu 04 Jun 2026 @ 10:00 AM (PDT)
AI Security Masters E9: READY OR NOT: Securing the AI Enterprise 1/5 - AI Agent SecurityWed 10 Jun 2026 @ 01:00 PM (EDT)
Deep Dive: When the Agents Attack: A Live Look at Agentic Exposure ValidationThu 11 Jun 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #8: Say Yes to AI Without Saying Yes to RiskThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeThu 04 Jun 2026 @ 07:00 PM (IDT)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - AmericaThu 04 Jun 2026 @ 10:00 AM (PDT)
AI Security Masters E9: READY OR NOT: Securing the AI Enterprise 1/5 - AI Agent SecurityWed 10 Jun 2026 @ 01:00 PM (EDT)
Deep Dive: When the Agents Attack: A Live Look at Agentic Exposure ValidationThu 11 Jun 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #8: Say Yes to AI Without Saying Yes to RiskFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY