> Source: [sk121605](https://support.checkpoint.com/results/sk/sk121605)

# sk121605 - No packet capture is received with IPS protection log

| Property | Value |
|----------|-------|
| Solution ID | sk121605 |
| Date Created | 2017-11-26 |
| Last Modified | 2022-08-02 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * Logs are received without packet capture for IPS protection, even if 'capture packets' checkbox is enabled on the protection properties in SmartConsole.
* Running kernel debug (`fw ctl debug -m fw + drop conn vm ips log dynlog cmi advp`) shows:  

  ```
  
  ;[cpu_1];[fw4_0];FW-1: fwloghandle_destroy: log handle ffffc2001f580198;
  ;[cpu_1];[fw4_0];fwloghandle_destroy: concurrent log handles allocated: 0;
  ;[cpu_1];[fw4_0];fw_kmsg_write_to_buf: copying 4 bytes for tsid 0. log_last=126088;
  ;[cpu_1];[fw4_0];fw_kmsg_write_to_buf: copying 4 bytes for tsid 0. log_last=126092;
  ;[cpu_1];[fw4_0];fw_kmsg_write_to_buf: copying 44 bytes for tsid 0. log_last=126096;
  ;[cpu_1];[fw4_0];cptraps_wake_up: called for tsid 0;
  ;[cpu_1];[fw4_0];fw_send_kmsg: log_start=ffffc2002379cccc, last=126140, first=126088;
  ;[cpu_1];[fw4_0];ips_gen_dyn_log: max_pcap_num=3 ;
  ;[cpu_1];[fw4_0];fwdynlog_perform_packet_capture : prepare forensics packet capture;
  ;[cpu_1];[fw4_0];fwdynlog_perform_packet_capture: match_opq or match_opq->streaming_vtable or match_opq->streaming_vtable->perform_capture or match_opq->output are null.;
  ;[cpu_1];[fw4_0];ips_gen_dyn_log: fwdynlog_perform_packet_capture() failed.;
  ;[cpu_1];[fw4_0]; ==>ips_log_struct_destroy:;
  ```

## Cause

Since R80.10, IPS blade is part of Threat Prevention policy, thus started using packet capture methodology of Threat Prevention.  
The new packet capture rely on PSL, which sometimes is missing when ips makes a detection. In these cases packet capture will not work.

## Solution

This problem was fixed. The fix is included in:

* [Check Point R80.30](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk144293)

Check Point recommends to always upgrade to the most recent version ([upgrade Security Gateway](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=downloads&product=435) / [upgrade Cluster](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=downloads&product=428) / [upgrade Security Management Server](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=downloads&product=184) / [upgrade Multi-Domain Security Management Server](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=downloads&product=166)).

For **other [supported](http://www.checkpoint.com/support-services/support-life-cycle-policy/index.html) versions** , Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
