- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Can you please show us the whole log, because I have a feeling theres more info if you scroll all the way to the bottom...also, what does that rule look like thats referenced in the description?
As below
did not find any attack name or any reason..
Phoneboy is right, TAC case might be good idea here...plus. ODD thing I find is why this shows 2 internal IP addresses? 10.233.x.x and 10.234.x.x. Personally, to me at least, that is very strange.
The funny thing about this log entry is that zero bytes were sent or received.
This might be worth a TAC case.
If this was an R80.20+ gateway, I'd surmise that the gateway updated itself with a new IPS signature but the management server didn't have that same IPS update, and therefore the SMS didn't know what to label the protection as in the log. Might not hurt to manually update your IPS signatures on the SMS.
The zero bytes sent and received may just indicate that the three-way TCP handshake never completed, as I believe those byte counters only consider data/payload bytes that appear once the handshake is complete. Is there MySQL actually listening on port 3306 at the destination IP shown in the log?
If I had to take a wild guess, I'd say it is probably the "MySQL General Settings" IPS signature since it has a "See Details..." configuration hyperlink similarly to the oddball "Core Protections" even though it is not explicitly labeled as such. The Core Protections are definitely different to work with and I covered them extensively in my IPS Immersion video course.
On the outside chance this is some kind of log indexer issue, try to locate this log entry using the old-school SmartView Tracker application (CPlgv.exe). Can you see the protection name there?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 16 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY