- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Interpretation of Network Activity report
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Interpretation of Network Activity report
How do you exactly correctly interpret this report?
Interpret1 has only 269 accept logs on internal firewall, which i hardly can believe given the amount of people that work here. Drop and Reject is a lot, which looks normal to me.
Interpret2 same -> low accept logs on internal firewall, although i know there is a lot of internall traffic.
Failover happened on this day, that's the reason why you see also high activity on IFW02. Normally IFW01 is the primary active one.
Interpret3 is report of 5 days, still low accept logs in internal firewall, Drop and Reject is a lot, which again looks normal to me
How is this possible when we log all rules in the policy where traffic has been accepted? Or how do i have to interpret this?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If it says Log and/or don't include Session info, they won't get indexed and won't appear in the reports.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Screenshot shows how it looks in our policy, quite normal i guess.
When looking at some log entries, indeed i could see that a lot of them don't have a Session tab.
I would have expected when you log your rules in your policy, that this would fully reflect in the Network Activity Report.
Is there a way to literally see all accept hits in the report?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Some additional discussion around this here: https://community.checkpoint.com/t5/Logging-and-Reporting/Creating-reports-with-tracking-quot-per-co...
