- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-09-2022 12:11 PM
I've got a new Global Protect portal/gateway. When I get connected to the gateway, I can see the connection via the GP monitor. Then if I go the to traffic monitor and search the source range 192.168.203.0/24 I only get traffic from previous testing that I've performed. I'm not getting the currently connected device to show up for some reason. It's connected as the remote user option in the network>gateway shows me connected and the ip of 192.168.203.2. However its not in the monitor. What do you all think?
03-09-2022 02:47 PM
Do you have a "receive_time" or interface/source/zone filter in you log view? If this is a new gateway/portal, did you create a new Security Policy rule allowing the traffic from the new interface/zone/IPs but didn't check the log options in the policy action?
03-10-2022 07:45 AM
My monitor is showing traffic from this IP. It was from previous connections to the gateway. It is a new portal/gateway. Yes, it has a security policy, all settings are correct as far as I'm seeing.
03-10-2022 08:00 AM
It's kind of hard to guess without details. I have seen a few errata in the release notes for various versions about edge cases where traffic wasn't being logged, but I don't recall anything specific about new gateways. Maybe open a support ticket with PA where you can share the details with them and they can see if it is something obvious.
03-10-2022 05:39 PM - edited 03-10-2022 05:39 PM
Hi @danoman2 ,
You probably have "log at session end" configured for your security policy rules. This is recommended. Monitor > Logs > Traffic will only show sessions that have ended. In order to see live sessions, go to Monitor > Session Browser.
Thanks,
Tom
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!