- Products
- Learn
- Local User Groups
- Partners
- More
Access Control and Threat Prevention Best Practices
5 November @ 5pm CET / 11am ET
Ask Check Point Threat Intelligence Anything!
October 28th, 9am ET / 3pm CET
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
Spark Management Portal and More!
Someone has turned on TCP state logging which is not enabled by default. This feature was mentioned in my Max Power 2020 book, pages 319-322. See sk101221: TCP state logging
Looks to me like in your case the TCP state updates are not being properly tacked on to the existing log entry; I would speculate that perhaps you only have session logging enabled for the rule matching this connection, but not connection logging which is I imagine where the TCP state updates will need to go. For the difference between the two see my 2022 CPX speech Max Gander: The Hidden World of Log Generation and...
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY