- Products
- Learn
- Local User Groups
- Partners
- More
Call For Papers
Your Expertise, Our Stage
Ink Dragon: A Major Nation-State Campaign
March 11th @ 5pm CET / 12pm EDT
AI Security Masters E4:
Introducing Cyata - Securing the Agenic AI Era
The Great Exposure Reset
AI Security Masters E3:
AI-Generated Malware
CheckMates Go:
CheckMates Fest
Hi,
We recently migrated IPSec Tunnel from CP 9100 to CP 3800 appliance.
Post migration we are unable to see th tunnel traffic logs on CP 3800.
Required blades is enable on CP3800 gateway.
What we are missing here ?
Are you seeing any logs for the 3800 or is it logging locally?
Use "cpstat fw -f log_connection" to check...
You cant see just vpn logs or any logs? Sorry, its not entirely clear from your description.
Best,
Andy
@the_rock unable to resolve the issue.
Let me explain the secnario once again, also attaching network diagram.
We are having 2 tier firewall architecture, Checkpoint we are using for Perimeter & Palo Alto for internel (core), server farm is behind the Palo Alto Firewall.
IPSec Tunnel is configured on Checkpoint, Tunnel is up, traffic from remote network is reaching to checkpoint, but we are unable to see the traffic on Palo Alto Firewall.
I suspect may be routing or NAT issue.
Ok...do you see any drops on CP side? What about PAN?
Palo Alto sidw we are not seeing any packet.
Then for sure sounds its issue on their end, not CP.
On CP fw, do this from expert -> fw ctl zdebug + drop | grep x.x.x.x
Just replace with right IPon other side. Its been forever since I worked with PAN, so not sure if they have similar command, but you can check the logs.
How we can verify trafiic is reaching to Palo Alto Interface via Checkpoint ?
Just do tcpdump or fw monitor. You can refer to below site my colleague made while back.
@the_rock issue got resolved.
It was routing issue from Palo Alto side.
Excellent, thanks for letting us know.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 11 | |
| 6 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 2 |
Tue 03 Mar 2026 @ 04:00 PM (CET)
Maestro Masters EMEA: Introduction to Maestro Hyperscale FirewallsTue 03 Mar 2026 @ 03:00 PM (EST)
Maestro Masters Americas: Introduction to Maestro Hyperscale FirewallsTue 03 Mar 2026 @ 04:00 PM (CET)
Maestro Masters EMEA: Introduction to Maestro Hyperscale FirewallsTue 03 Mar 2026 @ 03:00 PM (EST)
Maestro Masters Americas: Introduction to Maestro Hyperscale FirewallsFri 06 Mar 2026 @ 08:00 AM (COT)
Check Point R82 Hands‑On Bootcamp – Comunidad DOJO PanamáTue 24 Mar 2026 @ 06:00 PM (COT)
San Pedro Sula: Spark Firewall y AI-Powered Security ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY