- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Hello,
I would like to know how to check the log history in the console for a given VPN site to site.
We have a VPN site to site set up with another company, and there was a case that the VPN tunnel was broken for an hour, you can't see anything in the SMS logs, there is only an hour hole, the question is whether it is possible in the console to download logs from a given tunnel at a given time deeper hour.
Thank you very much for help
The sms version is R81.10
Firewall - r81.10
Logs at least should show why the tunnel went down and later up again ! If VPN is down it will not log.
Logs at least should show why the tunnel went down and later up again ! If VPN is down it will not log.
Thank you for your help
Hello,
Is there a way to see the “possible root cause” of why a VPN tunnel went down and then came back up, from one moment to the next?
We are having a problem with a VPN, which suddenly “crashes” and then starts working again after a while without any intervention.
Is there a file we can check that might help us with this?
Cheers 🙂
These kinds of "fails and comes back" issues with VPNs are usually caused by mismatches in the configuration on both ends (namely timers related to key renegotiation).
You might have a look at scenario 4 here: https://support.checkpoint.com/results/sk/sk108600
Hello,
Is there a relevant log in SmartConsole that could give us an “idea” of the possible root cause?
Is there any way to help find logs relevant to intermittent issues in the SmartConsole search engine?
I normally do "blade:VPN AND <public IP of peer>", then filter out accepted / encrypted traffic or filter on reject / key install or something like that, and I generally can fix any VPN issues doing that based on what the logs tell me.
Hello.
Regarding the “Key Install” log type, does it always represent a “problem” with an S2S VPN?
Is it something that needs to be “checked” in detail?
No, generally the "Key Install" is always a good thing and is an expected log, but I use it to confirm the tunnel is building how I expect it to, as the tunnel could be breaking because of the networks / hosts sent in Phase 2.
For this example, this is the exact IKE ID I expect to see, so I know the encryption domain is not the problem in this direction. This can work properly when 1 firewall initiates traffic and could break if the other side is to initiate as their configuration could be off slightly sending a /29 instead of a /28 or something.
You will see key installs line-up with the timers you have set here:
An example of an issue could be you are seeing "Key Installs" every 15 minutes when they should be around an hour, something is probably off.
Hello @CaseyB
Your last comment is precisely part of my problem.
I am seeing too many recurring Key Install logs for a specific VPN.
And the other problem is that every Friday morning, the VPN goes down and then comes back up without any intervention.
That is why I am trying to find a way to know if the logs show us a reason why this is happening.
You are going to see a "Key Install" for every IKE SA you are building on the tunnel. So, you do need to examine them to see if they are expected.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 9 | |
| 8 | |
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY