- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello All,
I have one query about logs if any one know the answer please reply the same.
query is between management servers and gateways logs sending in which format like plain text and encrypted form?
and if it’s sending logs in plain format is it possible to man in the middle attacker to read the logs while sending to management server?
Logs are sent through a protected channel with certificate-based authentication. I would be very surprised if you manage to do MitM attach on that.
Thanks for your reply is there any way we can show that logs was encrypted during forwarding logs management server, because auditor ask they same questions to us and if is it mentioned in any document please share if you have any docs or articles related to this topic.
Its pretty simple - Capture the packet in your switch for port TCP/257 or even on mgmt server for port TCP/257. Try to read the logs. Since mgmt server is CA and then distributes certificates to difference component like firewalls and event viewer if deployed separately. The entire communication is encrypted using certificates
Please refer to the section on SIC in the Security Management Admin Guide for your version, aswell as describing the encryption used by SIC it states this "trust" is required to send logs from Gateway to Management etc.
@usmanshah526 you can find these information in the documentation Secure Internal Communication (SIC)
encryption type, which communication is encrypted etc.
Also, to add to this, any communication between mgmt and gateway would be encrypted. Think of basic scenario...lets say SIC breaks on the firewall and you have to reset it. Key you put on for sic reset, does not matter, can be 12345678, its a one time password thats encrypted and its gone, thats it.
But, if you really need document stating than, I will let someone else provide it, as I had never seen one stating so.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 21 | |
| 20 | |
| 19 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY