Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
nagaraja_cs
Contributor

Unable to see logs for Packet Sanity Inspection Setting

Hi Team,

We have enable logging for Packet Sanity in Inspection Settings on Management Server.

We are unable to see the logs related to the above mentioned setting.

Please let me know if there is any specific filtering I should do for the logs.

You can refer the screenshot attached for the mentioned setting

0 Kudos
4 Replies
_Val_
Admin
Admin

This protection should be active and installed on a security gateway, and also triggered, to activate log entries. Look for Packet Sanity in the logs. If you do not see any, most probably protection is not triggered in the first place. 

0 Kudos
Timothy_Hall
Champion
Champion

On the Gateways screen of Inspection Settings, which profile is assigned to your gateway: "Default Inspection" or "Recommended Inspection"?  That will determine what actually happens on the gateway as you have two different Actions depending on the profile.

"Max Capture: Know Your Packets" Video Series
now available at http://www.maxpowerfirewalls.com
0 Kudos
nagaraja_cs
Contributor

Hi Timothy,

Attached screenshot is from the demo console, we have set this parameter for our customer environment but not able to see any logs related to Packet Sanity .Customer is planning to change the action to drop for this setting. We want to monitor the logs but we are not sure how to check these logs.

After changing the action to drop, how we can find if the traffic is dropping because of this setting.

0 Kudos
Timothy_Hall
Champion
Champion

I'll ask again: what Inspection Settings profile is assigned to your gateway?

"Max Capture: Know Your Packets" Video Series
now available at http://www.maxpowerfirewalls.com