> Source: [sk106838](https://support.checkpoint.com/results/sk/sk106838)

# sk106838 - Geo Protection mechanism logs connections from internal IP addresses

| Property | Value |
|----------|-------|
| Solution ID | sk106838 |
| Date Created | 2015-07-14 |
| Last Modified | 2019-05-05 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * When Geo Protection mechanism is activated, Geo logs are generated for connections originating from and destined to internally defined IP addresses, either by Security Gateway internal network interfaces, or by RFC 1918 (private IP address spaces), resulting in a massive volume of logs.

* Upon Geo Protection match, the "Source Country" field is populated according to the matching country in the rule base and not according to the actual country source IP (see [sk105019](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105019)).  

  Countries that are not included in the policy are logged as "OTR" in log's "Source Country" and "Destination Country" fields.

## Cause

Geo Protection is not processing connections inside private networks correctly.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
