RSA Admin

Checkpoint: inbound vs outbound

Discussion created by RSA Admin Employee on Aug 14, 2008
Latest reply on Sep 26, 2008 by RSA Admin

Does anyone know why a Firewall Accounting report always returns a "0" in the inbound/outbound column?  When I view the raw Checkpoint logs in the Event Viewer, I can clearly see which traffic is outbound and which traffic is inbound. However, there doesn't seem to be a way to run a report to filter out inbound vs outbound, unless I start parsing through the source/destination IPs for known internal addresses.

If the information is being capture in the raw logs, I imagine it must be saved somewhere to use in reporting.  Has anyone ever found this location?


Thanks in advance.

Outcomes