> Source: [sk120261](https://support.checkpoint.com/results/sk/sk120261)

# sk120261 - Geo Protection logs show the wrong country flag

| Property | Value |
|----------|-------|
| Solution ID | sk120261 |
| Date Created | 2017-09-17 |
| Last Modified | 2025-07-23 |
| Technical Level | Advanced |
| Products | Security Management Server, Multi-Domain Security Management Server |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82 |
| OS | Gaia |

## Symptoms

- * The country flag in the source and destination columns is a cosmetic feature that indicates the country of the IP according to an internal mapping DB,

* In some cases, the flag may not match the country according to the IP address that the Internet Assigned Numbers Authority (IANA) has assigned for that country.

## Cause

Important to emphasize that this is a cosmetic bug in logs presentation.

The internal mapping database (*ip2country.csv*) on the Security Management Server / Multi-Domain Management Server / SmartEvent Server / Log Server may not be up to date.

<br />

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
