> Source: [sk171728](https://support.checkpoint.com/results/sk/sk171728)

# sk171728 - In the Endpoint Security Client UI, the  Firewall blade shows "blocked" connections that Log Viewer does not show

| Property | Value |
|----------|-------|
| Solution ID | sk171728 |
| Date Created | 2021-02-04 |
| Last Modified | 2021-02-10 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |
| OS | Windows |

## Symptoms

- * In the Endpoint Security Client UI, the Firewall blade shows "blocked" connections that Log Viewer does not show.
* The Firewall blade in the Endpoint Security Client UI shows:  
  "Firewall has blocked xxxx connections in the last 24 hours."  
  ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1611755141890/fw202101270814521.png)

## Cause

In the Firewall blade client UI image above, you can see that the "Firewall has blocked 506 connections in the past 24 hours."  

All connection attempts are counted and displayed in the main UI window. When you see "Firewall has blocked 506 connections in the past 24 hours" this means there were **attempts** to reach a blocked IP address from this machine, or **attempts** to reach this machine from a blocked IP address. The total number of these attempts is 506.  

**Blocked connections in the Log Viewer are actual connections, and are not connection attempts.** The main UI window displays the number of blocked attempts. The Log Viewer displays every blocked connection (**only** if the user selected the "Log" or "Alert" options in the rule that blocks this connection, in SmartEndpoint).

<br />

## Solution

This is an expected behavior.

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
