- Products
- Learn
- Local User Groups
- Partners
- More
Access Control and Threat Prevention Best Practices
5 November @ 5pm CET / 11am ET
Ask Check Point Threat Intelligence Anything!
October 28th, 9am ET / 3pm CET
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
Spark Management Portal and More!
I am trying to figure out how to get mobile access to correctly report on users for:
1. Login/Logout Activity
2. Client they are currently using
3. Destination of their traffic
Firsts 2 I have been successful in creating the appropriate pages. However the 3rd doesn't seem to work no matter what I do.
On SmartEvent I created a new report with report filter as follows:
and on the page for my destinations I set the page with a table with settings as follows:
However no matter what I do the destination comes up blank:
Can someone enlighten me on what I'm doing wrong -have spent hours on the and if I put in "Destination port" into the table settings that shows up, the only thing I cannot get to show up is "Destination"
Hi Juan,
Try to add "contains" field and match the words. Let see if you are getting reports or not for destination.
"No data found" when I change my filter.
Which destination are you looking for here:
The server they are connecting to over vpn.
Sent from my iPhone
I found the issue it's not allowing VPN traffic data to be pulled into table view, is this by design??
Hi Jaun,
Are you talking about Mobile access SSL VPN? Please select "All Session events" in Mobile access blade for required field and check.
Mobile Access Blade --> Advance setting --> Logging --> Tracking
Please add a screen capture of a sample log card and mark all the relevant fields you wish to report on.
Then I will be able to advise you how to do it.
Kfir
Still trying to get this resolved:
Just a thought, have you tried applying a report filter of VPN blade and Source equal to the Office mode IP range, and then adding just source and destination to your table?
Yes doesn’t come up ☺
What version are the gateways and management on?
R80.10 – mobile access is not one of the fields you can add in the table
Just dealing with such report and have follwing suggestions for you:
1. Enable "logging per session" on all rules you want to track. VPN blade is not generating session logs, so no data for smartevent.
2. On your report use filter by action: Decrypt and can also filter for destination if applicable.
Where how it looks no my report:
Hope this helps
Thank you very much - will test per your settings.
That worked!! Thanks so much for the solution.
Hi,
I've read this thread with interest as I'm trying to do the same thing - reporting on what internal servers each Mobile Access user is hitting. I didn't quite follow when you suggested "logging per session". I presume you mean on the normal Security rules logging? In which case, which Security rule would I log to capture Mobile Access Native Application traffic?
Any help greatly appreciated.
Thanks,
Matt
Right click on Track field of relevant rule, select More.
Thanks Dameon Welch Abernathy. I was more interested in which Security rule I need to enable this logging. I thought that as I'm using Mobile Access, my access rules are created in the MAB rulebase rather than the Security rulebase, so I don't get which specific rule I should enable this per session logging on in order to capture what internal "Native Application" IP's my users are accessing?
Which Security rule (if any) matches the traffic?
Not sure if this works if you're not using the unified policy that includes Mobile Access or not.
Ah, Unified Policy! That makes sense... I'm not running Unified at the moment... I'll add that to my To-Do list!
Thanks.
I have put Office pool IPs in source field.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
21 | |
12 | |
7 | |
6 | |
4 | |
4 | |
4 | |
3 | |
3 | |
2 |
Tue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewTue 28 Oct 2025 @ 12:30 PM (EDT)
Check Point & AWS Virtual Immersion Day: Web App ProtectionTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewTue 28 Oct 2025 @ 12:30 PM (EDT)
Check Point & AWS Virtual Immersion Day: Web App ProtectionThu 30 Oct 2025 @ 03:00 PM (CET)
Cloud Security Under Siege: Critical Insights from the 2025 Security Landscape - EMEAThu 30 Oct 2025 @ 02:00 PM (EDT)
Cloud Security Under Siege: Critical Insights from the 2025 Security Landscape - AMERAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY