- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- Re: Threat Prevention logs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Threat Prevention logs
Hi CP,
Regrading to Threat Prevention log if we not see a few days it's cause from Policy or anything ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Could be several things probably best reviewed via a remote session rather than guessing.
With that said are you still receiving normal firewall logs from the same Gateways or no?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We got the firewall logs as normal on the same gateway. And just last few days that we did not get threat prevention logs.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Which JHF take is applied to this environment and are the relevant Threat Prevention blades still enabled on the gateway object?
Additionally would anyone have configured fast_accel rules recently?
Again, probably best to contact TAC to review via a remote session.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Threat prevention blades are still enable on the gateway object and as I mention we did not change anything on on that.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Again please provide all the requested info as follows:
- Which Jumbo/JHF version is installed on-top of R81.10?
- Output of command: fw stat -b AMW
- Run CheckME and review logs
If you don't wish to do so here for whatever reason then please consult further with TAC via a remote session to diagnose the problem more efficiently.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
May I ask you, Normally threat prevention logs are always detect right?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No they will typically be either Detect or Prevent depending on your configuration/policy and the type of threat encountered.
Please review your smartlog filters...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, I concern because it's just last week that I can not see the logs detection and prevention. That I think it may any issue.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There isn't sufficient information available here to say apart from the obvious categories
Please expand the IPS log card if you need further insight
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Might just be that the gateway is not sending logs:
Or some configuration issue.
Did you see TP logs before?
Do you see firewall logs?
Might be that the rule is set not to track?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can you check the Threat Prevention Policy is installed properly?
Please share the output of fw stat -b AMW on the Security Gateway
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We did not change anything on threat prevention policy. And just last few days did not get threat prevention logs.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Please provide output of fw stat -b AMW run on the gateway as requested earlier in the thread.
Exclusively at CPX 2025 Las Vegas Tuesday Feb 25th @ 1:00pm
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
http://www.cpcheckme.com will light up your Threat Prevention logs and tell you if it is working correctly.
Exclusively at CPX 2025 Las Vegas Tuesday Feb 25th @ 1:00pm
