> Source: [sk163412](https://support.checkpoint.com/results/sk/sk163412)

# sk163412 - Syslog over VPN reports random hostname or log origin

| Property | Value |
|----------|-------|
| Solution ID | sk163412 |
| Date Created | 2019-11-12 |
| Last Modified | 2019-11-13 |
| Technical Level | Advanced |
| Products | Spark Firewall (Locally Managed) |
| Versions | R82.00.X, R81.10.X |
| Platform | 910 |

## Symptoms

- When the SMB device has an external syslog and security log server configured behind the peer Gateway over VPN, the hostname or log origin may seem random.   
**Example** :

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk163412/Untitled1911130506.png)

## Cause

1. The advanced parameter "VPN Site to Site global settings - Use internal IP address for encrypted connections from local gateway" is used.
2. The Gateway randomly chooses one internal interface from which to send the encrypted connections.
3. In replication, more than one internal network that takes part in the VPN tunnel is used.
4. Currently, the Gateway chooses one interface randomly, from which it generates the encrypted connections.
5. Since the data inside the packet is correct, with the correct source and destination, there is no error here.
6. In order to have the origin IP be the same interface from which the traffic of a specific network is sent, a tunnel test will be sent from all internal interfaces in the Gateway that take part in the VPN: one interface per network, not only the random, internal one. This requires an RFE (see below).

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
