- Products
- Learn
- Local User Groups
- Partners
- More
Secure Your AI Transformation
9 April @ 12pm SGT / 3pm CET / 2PM EDT
Check Point WAF TechTalk:
Introduction and New Features
AI Security Masters E6: When AI Goes Wrong -
Hallucinations, Jailbreaks, and the Curious Behavior of AI Agents
Ink Dragon: A Major Nation-State Campaign
Watch HereAI Security Masters E5:
Powering Prevention: The AI Driving Check Point’s ThreatCloud
CheckMates Go:
CheckMates Fest
Hi,
We recently migrated IPSec Tunnel from CP 9100 to CP 3800 appliance.
Post migration we are unable to see th tunnel traffic logs on CP 3800.
Required blades is enable on CP3800 gateway.
What we are missing here ?
Ok...do you see any drops on CP side? What about PAN?
Are you seeing any logs for the 3800 or is it logging locally?
Use "cpstat fw -f log_connection" to check...
You cant see just vpn logs or any logs? Sorry, its not entirely clear from your description.
Best,
Andy
Hey @Mitesh
Were you able to fix this mate?
Andy
@the_rock unable to resolve the issue.
Let me explain the secnario once again, also attaching network diagram.
We are having 2 tier firewall architecture, Checkpoint we are using for Perimeter & Palo Alto for internel (core), server farm is behind the Palo Alto Firewall.
IPSec Tunnel is configured on Checkpoint, Tunnel is up, traffic from remote network is reaching to checkpoint, but we are unable to see the traffic on Palo Alto Firewall.
I suspect may be routing or NAT issue.
Ok...do you see any drops on CP side? What about PAN?
Palo Alto sidw we are not seeing any packet.
Then for sure sounds its issue on their end, not CP.
On CP fw, do this from expert -> fw ctl zdebug + drop | grep x.x.x.x
Just replace with right IPon other side. Its been forever since I worked with PAN, so not sure if they have similar command, but you can check the logs.
How we can verify trafiic is reaching to Palo Alto Interface via Checkpoint ?
Just do tcpdump or fw monitor. You can refer to below site my colleague made while back.
@the_rock issue got resolved.
It was routing issue from Palo Alto side.
Excellent, thanks for letting us know.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 13 | |
| 10 | |
| 8 | |
| 8 | |
| 6 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 |
Tue 07 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Check Point WAF and IO River: Multi-CDN Security in ActionWed 08 Apr 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: The Cloud Firewall with near 100% Zero Day prevention - In 7 LanguagesWed 08 Apr 2026 @ 07:00 PM (CST)
ERM al Descubierto: Amenazas Ocultas que Pondrán a Prueba tu Empresa en 2026Tue 07 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Check Point WAF and IO River: Multi-CDN Security in ActionWed 08 Apr 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: The Cloud Firewall with near 100% Zero Day prevention - In 7 LanguagesWed 08 Apr 2026 @ 07:00 PM (CST)
ERM al Descubierto: Amenazas Ocultas que Pondrán a Prueba tu Empresa en 2026Tue 14 Apr 2026 @ 03:00 PM (PDT)
Renton, WA: Securing The AI Transformation and Exposure ManagementThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY