Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
CP-NDA
Collaborator

Disable logging of a specific implied rule (Tunnel_test)

Hi,

 

Is there a way to disable the log a specific implied rule (tunnel_test) ?

 

We are getting thousand of logs and these are really useless.

 

We tried to turned off the log in the VPN community but it has no impact on the logs

 

Thank you

 

Nicolas

0 Kudos
5 Replies
G_W_Albrecht
Legend Legend
Legend

This could be a direct answer: sk110218: How to enable logging of informative implied rules on Security Gateway R80.10 and higher

Other possibility is to change the Permanent tunnel mode (see sk104760: ATRG: VPN Core).

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
CP-NDA
Collaborator

Hi,

 

Thank you for the answer however this SK is not describing how disable log for specific rule.

If I'm not wrong this will only provide more info about the involved implied rule in the logs.

We just want to disable the logging of a specific traffic without changing the time of permanent tunnel which is just fine

 

Thank you

0 Kudos
G_W_Albrecht
Legend Legend
Legend

No, this SK shows how to disable all logs for implied rules in part (3) How to disable the logging of informative implied rules on the Security Gateway. It lists the 3 implied rules for tunnel tests.

But would be a good question for TAC !

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
_Val_
Admin
Admin

Logging is for all implied rules.

Technically, you can edit implied_rules.def file on your management server, take tunnel test out AND add it a an explicit rule on top of your policy, but iI cannot really recommend this, as it is way harder to manage than filtering out logs you do not want to see in SmartView.

If you, however, want to go this road, look into sk92281 and sk104879.

Once again, not recommended.

0 Kudos
CP-NDA
Collaborator

Good to know

 

Seems to be a limitation as well

We've to chose to disable all logs or follow an not recommended method 🙂

Thank you for your help

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events