- Products
- Learn
- Local User Groups
- Partners
- More
Simplify Admin Operations with R82.20
Wed, 19 August @ 5pm CET/11am EDT
The industry's first AI Network Firewall
Securing AI traffic, everywhere
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
READY OR NOT: Securing the AI Enterprise
AI Research & Threat Landscape
CheckMates Go:
That's Serious Stuff!
Hi,
We use a mobile access portal, let's say portal.company.com
Let's say someone tries to attack us like this: portal.company.com/sslvpn<script>
They get an error screen which is provided by the GW:
I'm trying to find evidence for this request in the logs but can't find it.
Is it being logged? if yes, how can I filter the logs to find it?
Thanks
The Access Log won't necessarily show it, though it might show the HTTPS connection without the URL.
You might find it somewhere in $CPVPNDIR/log.
Hi PhoneBoy,
Couldn't find any log files under $CPVPNDIR (version 81.10).
Tried searching other folders such as "/opt/CPVPNPortal/logs" but couldn't find any relevant logs.
Hi G_W_Albrecht,
This is not the issue of this post, we're not having problems with our portal.
I'm just trying to find where are the logs for access attemps to this portal, which also includes the url entered.
I linked the SK because of:
Product: Mobile Access Reason: The requested destination is not configured for this user's group in the Mobile Access policy. Mobile Access Category: Web Access: Denied Resource: http://10.x.x.x:80/sig.php
Here the URL is displayed...
Oh, I see...
unfortunately I can't see such logs in my system (R81.10).
Also, this error page only pops up when you try somehing like "https://portal.company.con/gibrish" but if you try to access the login page and add parameters such as portal.company.com/sslvpn/Login/Login?script<1=1> it just ignores it, but I still want to know about it
Legacy SVTracker does not show much, too ! i would suggest to call CP TAC !
Have a look at /var/log/opt/CPcvpn-R81.10/log/httpd.log
Already tried that but this log only shows many error and fail messages such as:
[69152][13 Sep 15:18:30][fdt] getCurlCrlOcspDir: failed to create directory: curl_crl_ocsp
[69152][13 Sep 15:18:30] registry_root_reload: Could not reload: Registry file doesn't exists or corrupted. Reverting to old version.
[69152][13 Sep 15:18:30] cpIsDir: Calling cpIsDirEx: Permission denied
[69152][13 Sep 15:18:30] cpFileCopy: failed to fopen64 source file, calling fopen: Permission denied
[69152][13 Sep 15:18:30] cpFileCopy: failed to fopen source file: Permission denied
[69152][13 Sep 15:18:30] registry_revert_to_old_version: Revert error: failed to copy /opt/CPshrd-R81.10/registry/HKLM_registry.data.old -> /opt/CPshrd-R81.10/registry/HKLM_registry.data_69152.tmp: Permission denied
[69152][13 Sep 15:18:30] registry_root_reload: Could not reload: Revert failed, file doesn't exists or corrupted.
[69152][13 Sep 15:18:30] registry_root_reload: Could not reload: Registry file doesn't exists or corrupted. Reverting to old version.
[69152][13 Sep 15:18:30] cpIsDir: Calling cpIsDirEx: Permission denied
YOu have to record the exact time you open the link in browser and find that in log !
Well I did that of course, but the lines I pasted in my previous reply are the only ones I see in this log.
I don't know if it's supposed to be like this...
Open a SR# with TAC to get to the logs !
Hi,
Quick update - I contacted TAC but after many investigation they came to the conclusion that for these logs I need to enable some other blades that we don't have, and they redircted me to our account owner at Checkpoint...
Thank you for trying to help
Can you send me the TAC SR in a private message?
Sure, I've sent it in PM
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 156 | |
| 105 | |
| 15 | |
| 12 | |
| 11 | |
| 9 | |
| 8 | |
| 7 | |
| 6 | |
| 6 |
Wed 12 Aug 2026 @ 11:00 AM (EDT)
Beyond Phishing: Securing Email Against SaaS and AI-Driven ThreatsTue 18 Aug 2026 @ 01:00 PM (BRT)
IA: a nova linha de frente do endpoint - Todo ataque tem um antes, um durante e depois.Thu 20 Aug 2026 @ 08:30 AM (COT)
Medellin: Workspace Evolution: Hybrid Mesh Management - Visibilidad, Automatización e IAWed 12 Aug 2026 @ 11:00 AM (EDT)
Beyond Phishing: Securing Email Against SaaS and AI-Driven ThreatsTue 18 Aug 2026 @ 01:00 PM (BRT)
IA: a nova linha de frente do endpoint - Todo ataque tem um antes, um durante e depois.Thu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeTue 25 Aug 2026 @ 05:00 PM (CEST)
The State of Ransomware Q2 2026: This Quarter's Trends, and Their Impact on Your DefensesThu 20 Aug 2026 @ 08:30 AM (COT)
Medellin: Workspace Evolution: Hybrid Mesh Management - Visibilidad, Automatización e IAThu 20 Aug 2026 @ 06:00 PM (COT)
Medellin: Workspace Intelligence: IA Generativa en Acción para Equipos de SeguridadAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY