- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: Strange log - Originating from against
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Strange log - Originating from against
Hi,
I found a strange and recurring log "originating from against" for the blade IPS - see screenshot
No behavior, but a lot of this for all our firewall.
Firewall and MGMT are running version R80.20
Any idea for that point ?
Thanks,
Arthur
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This is related to the Log Suppression feature of Threat Prevention, which was covered by my 2022 CPX speech Max Gander: The Hidden World of Log Generation and Log Suppression at Check Point
Bottom line is that this is expected behavior, please see sk115876: Some fields are missing from IPS or Threat Prevention logs
CET (Europe) Timezone Course Scheduled for July 1-2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There is not much that can be said when the only detail we know here is the version 8)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Indeed, but what I can says...
We get this message from all firewall without an apparent reason.
Do you have already see this message ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Look into the logs in SVTracker - look for logs from the same source at the same time...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
OK so I try to find the same log with SVTracker, but no way to find it.
Regarding the othe logs from the same origin, we have a lot of accept and Drop (about 1600 entry for the same second) - icmp/tcp/udp - but only from the firewall blade.
This is the only log from IPS blade at this exact time from this specific origin.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
hello,
was there a solution for this? i currently have the same behaviour with our r81.20.
thanks
jeff
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This is related to the Log Suppression feature of Threat Prevention, which was covered by my 2022 CPX speech Max Gander: The Hidden World of Log Generation and Log Suppression at Check Point
Bottom line is that this is expected behavior, please see sk115876: Some fields are missing from IPS or Threat Prevention logs
CET (Europe) Timezone Course Scheduled for July 1-2
