- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi Team,
Since we most of the time dealing with Advanced debugging pertaining to customer issues. And those issues could be related to so many blades now there are lot many services that we need to debug or Check Point firewall has. Now the challenge is every process has its own debug procedure, flags and log location. I feel at at least more than 50+ processes and those are those many flags for every daemon.
Plus every debug logs has its own log location and need to keep in mind that as well.
Its very difficult to remember those flags debug procedure, log location and 99% of the time we need to search for ATRG which is really time consuming. Plus certain debugs are needs to be done for user specific as well and like trace user logs
This makes the overall troubleshooting very cumbersome and hectic.
Hence is this possible to have a some kind of uniform debug procedure as with other vendors and flags like follow nomenclature
where
fw <known_blade_name> debug on/off <debug_level>
fw vpn debug on
fw cvpn debug on
fw https debug on
fw urlf debug on
fw appi debug on level <1,2,3,4,5>
so on...
Plus store the logs at one location like /var/log/debug
Feel free to share to thoughts/questions/concerns -
@PhoneBoy or any other folks can raise my voice/concern to R&D/development team?
Best you do an RFE for this feature: https://rfe.checkpoint.com/rfe/rfe.htm
But honestly, i do not think you will succeed here because of the restless product extensions that happen since more than 20 years... And i am rather lucky that it needs technical expertise, broad knowledge and good memory to do advanced debugging - otherwise, no one would pay me as a support provider if it is all so very simple 8).
But why do you not write yourself a bash script incorporating all the debug variants you are using and control them by menue ? You would not have to look the commands up again and again.
Hi,
Yes I already punched in the RFE and I know its not easy but I thought to give a try. Script could be a good idea but again clearing the flags once the debug is over is equally important hence I feel it need a manual intervention
Technically this is VERY hard to achieve.
As for the scripts, TAC has them, if you are doing troubleshooting with their assistance, ask upfront. Not 100% coverage though, different ones for specific cases.
R&D does read and participate in the community.
While I agree it would be ideal if there were a more "uniform" way to enable debugging, in practice this is not such an easy thing.
A given piece of functionality may rely on several infrastructures "under the hood."
Enabling lots of debug messages will create a performance issue and it needs to be done fairly precisely to minimize the potential impact.
Hi,
We understand the difficulty in debugging such a large system and we are working on optimization and improving this procedure.
We are currently working on multiple changes that address those issues such as
* Debug tools – allow you to run the required debug without knowing the syntax
* Unified debug files – combine important messages from different debugs files into a unified file.
The above is still under development and we will update once integrated into our product.
Yeah we as a administrator are not bothered about remembering the syntax but the different flags different places for log files is really cumbersome hence wondering if something unified can be made. It would be very great if such feature can be made available.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 16 | |
| 12 | |
| 8 | |
| 7 | |
| 6 | |
| 4 | |
| 3 | |
| 3 | |
| 2 | |
| 2 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY