"Is the rule number added later at all? accounting has the habit to hold 
back on information untill the session is done for a while."

never added at all.  I do however, see rule number for DNS traffics.  With
telnet traffics, I exit the telnet connection but still no rules number in the
log for telnet connection, even after 3 days.

"Do you have multiple objects with the same IP address?"

NO

Hugo van der Kooij <[EMAIL PROTECTED]> wrote: On Thu, 23 Aug 2007, cisco4ng 
wrote:

> Provider-1 NG/AI R55 with HFA_20 on SPLAT.  Enforcement modules
> is running Active/Active with floodgate on SPLAT NG/AI R55
> with HFA_20.
>
> I have a simple rule on the CMA for these two enforcement modules:
>
> Any Any DNS  Accept account
> Any Any telnet Accept account
> Any Any Any   Accept account

Does this also apply if you use log instead of account?
Is the rule number added later at all? accounting has the habit to hold 
back on information untill the session is done for a while.

> The problem is that under "log" of the SmartView tracker,
> I do NOT see the rule # in the column section.  It shows
> up as blank.  Why?  Is it a bug or what?

If you can replicate it:
  1. Create cpinfo files
  2. Open a ticket
  3. Preferably give them access to you lab setup and let them see for them 
selves.

I find that step 3 is more convincing then step 2.

> The other issue I have is that I have a group-object called
> "TEST" and in this object-group, I have about 20 hosts
> in this TEST group-object.  I have a host object called
> "pornstar_192.168.1.10" and this host object is NOT
> a member of the group-object "TEST".  However, when
> I perform a querry, it showed that "pornstar_192.168.1.10"
> host object is part of the group object "TEST".  Why?

Do you have multiple objects with the same IP address?

Hugo

-- 
  [EMAIL PROTECTED] http://hugo.vanderkooij.org/
      This message is using 100% recycled electrons.

  Some men see computers as they are and say "Windows"
  I use computers with Linux and say "Why Windows?"
  (Thanks JFK, for this quote of George Bernard Shaw.)

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================


       
---------------------------------
Shape Yahoo! in your own image.  Join our Network Research Panel today!

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to