- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Hey guys,
I hope someone might be able to shed some light about this. So, while back, I set up a lab with base R81, mgmt server + 2 single gateways and all works fine, no issues. I upgraded all to R81.10 and still going strong : -).
Now, the other week, to demonstrate R81.10 from scratch to a customer, I built brand new R81.10 (mgmt server + HA cluster) and all seems fine, except I see some odd issues with logging. For example, if I refresh the logs in dashboard, looks okay, but...say if I ping 8.8.8.8 from either cluster member, I can never see any logs, which is not the case in my other lab (works fine). I followed support sk's for this, rebooted many times, did fw logswitch, literally all the steps and still no luck.
I am totally at a loss why this would be happening, makes no logical sense to me.
If anyone can provide some suggestions, I would appreciate it. Anyway, its nothing urgent, since its a lab, but its really puzzling to me why its not working.
tx as always!!
Outbound traffic from the gateway is almost always handled through an implied rule that doesn't log, last I checked...
Outbound traffic from the gateway is almost always handled through an implied rule that doesn't log, last I checked...
Thanks @PhoneBoy . That makes sense, but then how come I see the log via right policy in my other lab?
Not sure, maybe the implied rules were changed?
Or perhaps there is a code changes that impacts this behavior somehow?
I hope you enable log in the rule that allows the traffic, my thought !
I know even after 15 years it would be easy to forget, but it was enabled ;). I think @PhoneBoy is correct.
Definitely no change in implied rules.
Make sure the date and time are correctly configured on gateway and management (log server). You might see logs with huge delays while the date is not correct on one of devices. Best to use NTP to avoid issue.
Thanks @JozkoMrkvicka , but that was not the issue, it was the first thing I checked actually. @PhoneBoy was 100% correct as usual...no offense to anyone else, but he is after all CP master/guru/legend/expert...whatever you want to call it :). I enabled to log implied rules and sure enough, it started to show logs to google dns right away. Funny enough, that option was NOT enabled in R81 and logs were showing actual rule number.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 29 | |
| 12 | |
| 12 | |
| 8 | |
| 8 | |
| 7 | |
| 7 | |
| 6 | |
| 5 | |
| 5 |
Tue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceWed 13 May 2026 @ 11:00 AM (EDT)
TechTalk: The State of Ransomware Q1 2026: Key Trends and Their ImpactThu 14 May 2026 @ 07:00 PM (EEST)
Under the Hood: Presentando Check Point Cloud Firewall como ServicioTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceTue 19 May 2026 @ 06:00 PM (IDT)
AI Security Masters E8 - Claude Mythos: New Era in Cyber SecurityAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY