sk180403 - Non-Transparent Proxy configuration is missing the IP address of the destination website in the URL Filtering logs
Non-Transparent Proxy configuration is missing the IP address of the destination website in the URL Filtering logs
Product: Application Control, Security Gateways, URL Filtering
Version: R80.10 (EOS), R80.20 (EOS), R80.30 (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20
OS: Gaia
Last Modified: 2025-01-21
Symptoms
- When the Security Gateway is configured in Non-Transparent Proxy Mode, the 'Destination' field in the URL Filtering logs is the Security Gateway's proxy interface. In the log with the client source IP address, there is no indication of the actual IP address of the target website.
Cause
This is by design. When you use a Non-Transparent proxy, the Security Gateway splits the connection and connects to the target destination sourced from the gateway instead of to the client. The client-based log shows a connection to the proxy interface of the Security Gateway.
Solution
This problem was fixed. The fix is included in:
- Check Point Quantum R82
- Jumbo Hotfix Accumulator for R81.20 starting from Take 26
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2023-01-08
Last Modified: 2025-01-21