SunScreen EFS Release 3.0 Reference Manual

Logging Limitations

  1. During a situation or time when there is excessive traffic through the Screen, not all packets are logged.

    This logging limitation is an isolated instance and depends on how fast your system runs.

  2. Decrypted packets are logged, but SKIP certificate IDs are not logged.

    SunScreen EFS 3.0 cannot guarantee the identity of who is coming through the firewall from an audit point of view.

  3. Only the active system logs packets.

    When the active HA cluster Screen fails, its logs are lost, and the new active HA cluster Screen begins logging the packets.