- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi,
We use a mobile access portal, let's say portal.company.com
Let's say someone tries to attack us like this: portal.company.com/sslvpn<script>
They get an error screen which is provided by the GW:
I'm trying to find evidence for this request in the logs but can't find it.
Is it being logged? if yes, how can I filter the logs to find it?
Thanks
The Access Log won't necessarily show it, though it might show the HTTPS connection without the URL.
You might find it somewhere in $CPVPNDIR/log.
Hi PhoneBoy,
Couldn't find any log files under $CPVPNDIR (version 81.10).
Tried searching other folders such as "/opt/CPVPNPortal/logs" but couldn't find any relevant logs.
Hi G_W_Albrecht,
This is not the issue of this post, we're not having problems with our portal.
I'm just trying to find where are the logs for access attemps to this portal, which also includes the url entered.
I linked the SK because of:
Product: Mobile Access Reason: The requested destination is not configured for this user's group in the Mobile Access policy. Mobile Access Category: Web Access: Denied Resource: http://10.x.x.x:80/sig.php
Here the URL is displayed...
Oh, I see...
unfortunately I can't see such logs in my system (R81.10).
Also, this error page only pops up when you try somehing like "https://portal.company.con/gibrish" but if you try to access the login page and add parameters such as portal.company.com/sslvpn/Login/Login?script<1=1> it just ignores it, but I still want to know about it
Legacy SVTracker does not show much, too ! i would suggest to call CP TAC !
Have a look at /var/log/opt/CPcvpn-R81.10/log/httpd.log
Already tried that but this log only shows many error and fail messages such as:
[69152][13 Sep 15:18:30][fdt] getCurlCrlOcspDir: failed to create directory: curl_crl_ocsp
[69152][13 Sep 15:18:30] registry_root_reload: Could not reload: Registry file doesn't exists or corrupted. Reverting to old version.
[69152][13 Sep 15:18:30] cpIsDir: Calling cpIsDirEx: Permission denied
[69152][13 Sep 15:18:30] cpFileCopy: failed to fopen64 source file, calling fopen: Permission denied
[69152][13 Sep 15:18:30] cpFileCopy: failed to fopen source file: Permission denied
[69152][13 Sep 15:18:30] registry_revert_to_old_version: Revert error: failed to copy /opt/CPshrd-R81.10/registry/HKLM_registry.data.old -> /opt/CPshrd-R81.10/registry/HKLM_registry.data_69152.tmp: Permission denied
[69152][13 Sep 15:18:30] registry_root_reload: Could not reload: Revert failed, file doesn't exists or corrupted.
[69152][13 Sep 15:18:30] registry_root_reload: Could not reload: Registry file doesn't exists or corrupted. Reverting to old version.
[69152][13 Sep 15:18:30] cpIsDir: Calling cpIsDirEx: Permission denied
YOu have to record the exact time you open the link in browser and find that in log !
Well I did that of course, but the lines I pasted in my previous reply are the only ones I see in this log.
I don't know if it's supposed to be like this...
Open a SR# with TAC to get to the logs !
Hi,
Quick update - I contacted TAC but after many investigation they came to the conclusion that for these logs I need to enable some other blades that we don't have, and they redircted me to our account owner at Checkpoint...
Thank you for trying to help
Can you send me the TAC SR in a private message?
Sure, I've sent it in PM
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
17 | |
12 | |
7 | |
6 | |
6 | |
6 | |
6 | |
5 | |
3 | |
3 |
Fri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY