- Products
- Learn
- Local User Groups
- Partners
- More
Scaling Check Point Automation with Arodonata
7 October @ 5pm CET / 11am EDT
What's New in Check Point SASE
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
AI Security Masters
Implementing the AI Security Trifecta
CheckMates Go:
Half is Not Enough
Hi,
We recently migrated IPSec Tunnel from CP 9100 to CP 3800 appliance.
Post migration we are unable to see th tunnel traffic logs on CP 3800.
Required blades is enable on CP3800 gateway.
What we are missing here ?
Ok...do you see any drops on CP side? What about PAN?
Are you seeing any logs for the 3800 or is it logging locally?
Use "cpstat fw -f log_connection" to check...
You cant see just vpn logs or any logs? Sorry, its not entirely clear from your description.
Best,
Andy
Hey @Mitesh
Were you able to fix this mate?
Andy
@the_rock unable to resolve the issue.
Let me explain the secnario once again, also attaching network diagram.
We are having 2 tier firewall architecture, Checkpoint we are using for Perimeter & Palo Alto for internel (core), server farm is behind the Palo Alto Firewall.
IPSec Tunnel is configured on Checkpoint, Tunnel is up, traffic from remote network is reaching to checkpoint, but we are unable to see the traffic on Palo Alto Firewall.
I suspect may be routing or NAT issue.
Ok...do you see any drops on CP side? What about PAN?
Palo Alto sidw we are not seeing any packet.
Then for sure sounds its issue on their end, not CP.
On CP fw, do this from expert -> fw ctl zdebug + drop | grep x.x.x.x
Just replace with right IPon other side. Its been forever since I worked with PAN, so not sure if they have similar command, but you can check the logs.
How we can verify trafiic is reaching to Palo Alto Interface via Checkpoint ?
Just do tcpdump or fw monitor. You can refer to below site my colleague made while back.
@the_rock issue got resolved.
It was routing issue from Palo Alto side.
Excellent, thanks for letting us know.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 24 | |
| 18 | |
| 15 | |
| 12 | |
| 7 | |
| 7 | |
| 6 | |
| 6 | |
| 5 | |
| 4 |
Mon 28 Sep 2026 @ 03:00 PM (CEST)
La nouvelle réalité des attaques DDoS: autonomie, échelle et avenir de la défenseThu 01 Oct 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point WAF | Preventing minus-zero-day attacksMon 28 Sep 2026 @ 03:00 PM (CEST)
La nouvelle réalité des attaques DDoS: autonomie, échelle et avenir de la défenseThu 01 Oct 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point WAF | Preventing minus-zero-day attacksAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY