cancel
Showing results for 
Search instead for 
Did you mean: 
Create a Post

fw rule set to track none but still logging

Hey all,

I want to disable the logs on a http/https firewall rule that generate tons of log, the goal is to get only the logs generated by the application control and url filtering blades.

I simply configure the firewall rule track action to "none" but I'm still get the logs of that rules.

someone can explain me why?

thank you.

16 Replies
Vladimir
Pearl

Re: fw rule set to track none but still logging

Check if the traffic you are seeing being logged belongs to any of the "Implied" rules and if you have "Log Implied Rules" setting enabled:

Re: fw rule set to track none but still logging

i’ts not an implied rule because on the log i see the rule number that is configured to not log

Re: fw rule set to track none but still logging

what does the "rule number" column in the log card say?

Re: fw rule set to track none but still logging

i see the rule number that i set to no logging.

0 Kudos

Re: fw rule set to track none but still logging

Are you sure that you installed that particular policy on that particular gateway?

If you did, please open a ticket so that Check Point Support will be able to investigate. 

Re: fw rule set to track none but still logging

I have only one cluster of gw, I'll open a tac.

thank you.

Re: fw rule set to track none but still logging

Please first check your logs and rulebase regardless of the presented rule number - it may well be that a wrong rule number is reported in the logs, so please double-check with source and dest of the packets.

Admin
Admin

Re: fw rule set to track none but still logging

I'm with Tomer, please open a TAC case so we can investigate.

Contact Support | Check Point Software 

0 Kudos
Danny
Pearl

Re: fw rule set to track none but still logging

Astardzhiev
Nickel

Re: fw rule set to track none but still logging

Try to install database to sync the rule number from the policy with the number represented in the logs. I am not sure if it will help, but I believe it is something that definitely need to do first and will not cost you anything.

R77.30  - Go to SmartDashboard -> Menu (top left corner)-> Policy -> Install Database
R80.10 - Go to SmartConsole -> Menu (top left corner) -> Install Database

Ni_c
Nickel

Re: fw rule set to track none but still logging

FYI,

This rule number mismatch in the logs is fixed in R80 and later versions. Install database not required. 

Re: fw rule set to track none but still logging

Has anyone fixed this issue. I also have a rule that I changed the "Track" from Log to None. I have tried multiple things without success. Here is what I have tried and what I am seeing:

I have (2) Gateways- One is a 2200 (having issues) and other is 3200 (no issue)

I have separate policies for each Gateway

Changed the Track on Both policies from LOG to NONE for DNS Traffic.

Pushed both policies 2200 still logging DNS traffic under Rule#2

Tried DELETING rule and Re-Creating in thinking there was a database issue or something hung, still didn't fix it.

Any advice would be greatly appreciated.

0 Kudos
Vladimir
Pearl

Re: fw rule set to track none but still logging

Just for kicks, please create a duplicate rule by hand under the one that is misfiring.

Disable original rule and install the policy.

Let us know if you are seeing the DNS traffic logged and if number of hits on the new rule is incrementing.

Re: fw rule set to track none but still logging

Yeah I have already tried that and it adopted the new rule # while logging. I also moved it down the policy a few columns and it followed as well. I am not sure what is going on with it this firewall policy. 

Just weird I have the 3200 working fine but the 2200 is not. The only other thing I have noticed is with the HFA's. I have them scheduled to download auto with manual install, but on the 2200 I am still on HFA 70 and when I search either through CPUSE on WebUI or CLI it says I am current???  While the 3200 is at HFA154.

0 Kudos

Re: fw rule set to track none but still logging

Please post the full log card with the IP addresses (and any other identifying information) redacted.  Make sure to expand all sections and show everything on all tabs.  Wondering if these logs are coming from some other part of the Access Policy such as Inspection Settings, Geo Policy, Mobile Access, or QoS; perhaps even Implied Rules although Danny mentioned those earlier in the thread.

--
Second Edition of my "Max Power" Firewall Book
Now Available at http://www.maxpowerfirewalls.com

"IPS Immersion Training" Self-paced Video Class
Now Available at http://www.maxpowerfirewalls.com
0 Kudos
Highlighted

Re: fw rule set to track none but still logging

I don't know if I should do a manual update of CPUSE Agent and HFA or is there some sort of limitation on the 2200. I did notice the build are the same along with the Kernel. 

0 Kudos