Connection logging limitations

Connection logging limitations are restrictions that prevent certain types of network connections from being logged by firewall systems.

Connection types that cannot be logged

Connection logging cannot capture information for these connection types:

  • The outer session of a plaintext, passthrough tunnel whose encapsulated connections are inspected by access control.

  • TCP connections if the three-way handshake is not completed, to avoid denial-of-service attacks against your firewalls. To monitor or debug failed connections, you can use the packet capture feature (Packet Capture Overview).