Hello Team.
Is traffic blocked by the “Inspection Settings” feature in Check Point ‘mandatorily’ labeled as “Inspection Settings” within a LOG?
I'm providing relevant information from the log to explain my question.
Id: 0a7b5e81-5105-ba02-691d-e64d5dd70000
Marker: @A@@B@1763566642@C@1516930
Domain: CMA_MIR
Time: 2025-11-19T15:46:21Z
Interface Direction: inbound
Interface Name: bond2.794
Id Generated By Indexer: false
First: true
Sequencenum: 249
Policy Rule UID: 837284bb-df97-41cd-a8e6-8a8d314623e2
Sub Policy Name: PQ_MIRNET Network
Sub Policy Uid: c4bdc336-5d7e-43e4-8bb3-9a07cfb6f724
Service ID: sip
Source: 10.11.51.14
Source Port: 31857
Destination: 147.219.18.19
Destination Port: 5060
IP Protocol: 17
Request: 180
Source IP-phone: 983667441
Destination Phone Number:51995109913
VoIP Call ID: 1f63acc7-d1b3-4b91-a7a6-23f8b0579819
VoIP Log Type: Security
Content Type: VoIP Session
Inspection Item: Number of retransmissions exceeded the maximum allowed
Inspection Information: Message exceeded the retransmissions limit
Severity: Medium
Performance Impact: Very Low
Inspection Category: protection
Inspection Profile: Default Inspection
Action: Drop
Type: Log
Policy Name: PQ_MIR
Db Tag: {D25FE155-9792-614A-A674-0FDAD2EE6F55}
Policy Date: 2025-11-10T18:48:03Z
Service: UDP/5060
Product Family: Access
Logid: 65536
Access Rule Name: VPN_AWS
Access Rule Number: 90
Interface: bond2.794
Description: sip Traffic Dropped from 10.11.51.14 to 147.219.18.19
Blade: IPS, Firewall
So, my question arises when reviewing the LOG, as I was sure that within the log there should be a section called “INSPECTION SETTINGS DETAILS” so that I could “understand” that this traffic block is due to this Check Point feature. but in my case, there is nothing in the log that indicates this section, and the most relevant thing I see is what is highlighted in bold above.
Does the INSPECTION SETTINGS functionality focus on all protocols or just some?
I have searched the IPS Protections for any signature related to this block, but nothing appears. The only thing I found is a “signature” in the INSPECTION SETTINGS section, but since nothing appears in the LOG that mentions “INSPECTION SETTINGS” I have not given it any importance, but apparently I should 😑
Thank you for your comments.