- Products
- Learn
- Local User Groups
- Partners
- More
The Great Exposure Reset
24 February 2026 @ 5pm CET / 11am EST
CheckMates Fest 2026
Watch Now!AI Security Masters
Hacking with AI: The Dark Side of Innovation
CheckMates Go:
CheckMates Fest
Hi mates,
I have a question.
Is it possible to forward logs to a SIEM using TCP without SSL/TLS when using Smart-1 Cloud?
According to the documentation, this seems to be supported:
https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Check-Point-SmartCloud-Admin-...
However, when I contacted TAC, they advised that it’s better to use TLS.
I was wondering if anyone has a working TCP (non-SSL) configuration in production.
Also, does the choice of protocol depend on the specific SIEM being used?
Thanks in advance.
When I look at the documentation, it clearly states that both SSL-encrypted forwarding and plain forwarding are supported.
The choice of protocol, whether TLS, plain or UDP, depends on what your SIEM supports. Tac's statement is, of course, correct. Encrypted transmission should always be preferred to plain text transmission, even if plain text is supported and works.
100% right Vincent
We only need to set up this configuration with Tufin, and the Tufin team told us that they support UDP on port 514 and TLS.
However, as far as I know, we already tried UDP, and it doesn’t seem to be working.
Did you work like discussed here?
https://forum.tufin.com/support/kc/latest/Content/Suite/cp_log-exp_R81.20.htm
I'm an S1C layman, I'm just trying to brainstorm a little.
Hey bro,
100% possible. We do it for few customers to siem solution. There is TAC case currently for new CP customer using S1C where we have an issue doing it for tcp protocol, so TAC is working on that. You just do it from the portal itself, see below.
Apparently, I wasn't that far off the mark. 🙂
You got it. @RemoteUser , I know 2 customers where we have this working with tcp/over tls as well. Just not sure this issue we currently have if it is siem or not. TAC guy said he believes it could be log rate problem, but they are still checking it.
Will update you once we have a solution.
https://support.checkpoint.com/results/sk/sk182699 this cloud be a possible solution?
100%. Sorry, forgot about it. TAC gave us that sk last week as well.
ok but since we want to export all the logs of the managment i need to configure this rule on all the policy package of the cma?
Sounds like that, yes.
Hey brother,
Were you able to sort this out?
Hi Andy,
Yes, Check Point is sending the logs without any issues. It looks like there’s something in between that’s interfering and causing the logs to arrive incompletely at Tufin.
I will let you know how we fix the issue we have with new CP customer. TAC is telling us that all on S1C side is fine, but its so weird, because if we change to send logs say using udp and random port, works for few seconds at a time, or 1 minute, then stops.
Hey brother,
We spent many hours troubleshooting this. TAC even verified all was fine on S1C side, nat rule was 100% right, but ended up being that we changed cluster object IP from external to internal, modified link selection, pushed policy, then all worked fine, we can now see logs. Appears logs were being sent over maas tunnel interface for some reason, rather than external, like what happens witt environments where this does work.
Hi Bro - whic nat rule ? this ? https://support.checkpoint.com/results/sk/sk182699
Nope...thats regular rule, Im talking about actual nat rule. In this dst is wan IP of the cluster (VIP) and then dst is log collector.
Ah, got it 😄 that’s why it seemed strange to me to talk about NAT with that rule 😄
Always good to be sure 🙂
By the way, as far as source of the regular policy (NOT nat one), you can obviously include whatever else needed. We added our SASE ip as well, as we always connect to it.
Hi,
Event Forwarding from the portal also supports TLS (non-SSL) configuration.
Are there any customers interested in enabling this? If so, we’d be happy to assist and gather feedback.
Step 4 in the attached:
https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Infinity-Portal-Admin-Guide/C...
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 27 | |
| 19 | |
| 10 | |
| 9 | |
| 7 | |
| 7 | |
| 7 | |
| 6 | |
| 5 | |
| 4 |
Thu 19 Feb 2026 @ 03:00 PM (EST)
Americas Deep Dive: Check Point Management API Best PracticesMon 23 Feb 2026 @ 11:00 AM (EST)
Latest updates on Quantum Spark including R82 features and Spark Management zero touch - AMERTue 24 Feb 2026 @ 10:00 AM (CET)
Latest updates on Quantum Spark including R82 features and Spark Management zero touch - EMEAThu 19 Feb 2026 @ 03:00 PM (EST)
Americas Deep Dive: Check Point Management API Best PracticesMon 23 Feb 2026 @ 11:00 AM (EST)
Latest updates on Quantum Spark including R82 features and Spark Management zero touch - AMERTue 24 Feb 2026 @ 10:00 AM (CET)
Latest updates on Quantum Spark including R82 features and Spark Management zero touch - EMEAFri 06 Mar 2026 @ 08:00 AM (COT)
Check Point R82 Hands‑On Bootcamp – Comunidad DOJO PanamáAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY