- Products
- Learn
- Local User Groups
- Partners
- More
Access Control and Threat Prevention Best Practices
5 November @ 5pm CET / 11am ET
Ask Check Point Threat Intelligence Anything!
October 28th, 9am ET / 3pm CET
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
Spark Management Portal and More!
can i create log filter that only shows traffic blocked "dropped" because of Geo-location inbound enforcement?
Log server is R81.10
You can do something like this in log search:
src_country: "Israel"
You can apply same logic to dst country
dst_country: "China"
hmmm not working for me
Not sure what to tell you then...I just did 3 filters on customer's environment and did below:
src_country: "Canada"
dst_country: "Canada"
dst_country: "China"
All 3 worked fine...can you attach a screenshot?
Well, works the same way, with or without the quotes : - )
If you're using the new Geo Policy (In Access Control policy) I suggest you filter by rule name.
If you're not using the new Geo Policy I suggest to move to the new. It's better and future features would be available for it.
Here's how:
1) Go to Access Control policy
2) Add a new rule and in the source/destination you can click on the "+" , Import -> Updateable Objects... (see attached picture).
3) In the object, search for "GEO Locations", and further select the countries you wish to use in the rule. You can use multiple countries per rule.
4) Define action and in the track put the desired log level.
5) Install policy.
Hi,
Given that many people will be using updatable objects rather than the old geo-policy, being unable to search logs directly by country seems to be quite a limitation. The suggestion of adding additional rules to allow filter based on rule UID is not a great workaround for (most) environment where change control is required for a rule.
"I need to add a rule because the product does not permit viewing logs by country"... If it's possible to display the flag in the log view then surely it must be possible to extend this to a search field. This shouldn't need a RFE, it should be included already.
Paul
You dont need to add any rules to search by country, works fine by using src_country and dst_country filters as examples we gave in the post.
Andy
I'm using R81.20 JHF 26 SC/GW and it's not working. If I filter on src_country:"New Zealand" all I see is my Mobile Access logs - despite there being numerous firewall blade logs from New Zealand sources. I even have NZ as an updatable object in a rule.
Again, the log viewer can show a flag, I shouldn't need to import updatable objects to filter in the log viewer.
Thats very odd, because I mever had the issue even back in R81.10. I agree with your assesment that you should not need to import updatable object to do the filter. Are you able to send a screenshot of the filter?
Andy
Current logs on the firewall blade showing traffic from Australia:
Attempt to filter by country shows no logs:
I went for Aussie as it removes the chance of some issue with spaces in the country name. I've tried without the quotes, with single quotes... nada
If I remove the filter on blade and change to src_country:"New Zealand" then I can see my VPN RAS connections from yesterday:
I just found that one of our customers had this issue last year and it was solved by running cloudguard stop and cloudguard start on the mgmt server. Not saying it will work for you, but worth a try. If not, I would maybe reach out to TAC to see what they advise. Also, does not hurt to reboot the mgmt server either, as it does not cause any traffic issues.
Andy
That sounds like the service desk: "have you tried turning it off and on again?" 🙂 Does appear to work as often for infrastructure as endpoints...
No change restarting the CloudGuard controller or cpstop/cpstart. TAC request would require having a customer wanting me to spend more of their time on this!
Exporting to CSV from SmartView includes columns src_uo_name and dst_uo_name (source/destination updatable object name"), so if you have the updatable objects defined (and probably active in a rule) you could use SmartView - but hardly convenient. You seemingly can't filter on these columns (src_uo_name etc) in SmartConsole either.
Sorry mate, not sure what else to suggest. I had never had this problem myself, so if those things we discussed did not work, then only other logical options I see are either TAC case or see if someone else on here might have a better suggestions.
Cheers,
Andy
 
					
				
				
			
		
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count | 
|---|---|
| 22 | |
| 16 | |
| 7 | |
| 6 | |
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | 
Tue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewTue 28 Oct 2025 @ 12:30 PM (EDT)
Check Point & AWS Virtual Immersion Day: Web App ProtectionTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewTue 28 Oct 2025 @ 12:30 PM (EDT)
Check Point & AWS Virtual Immersion Day: Web App ProtectionThu 30 Oct 2025 @ 03:00 PM (CET)
Cloud Security Under Siege: Critical Insights from the 2025 Security Landscape - EMEAThu 30 Oct 2025 @ 11:00 AM (EDT)
Tips and Tricks 2025 #15: Become a Threat Exposure Management Power User!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY