> Source: [sk180442](https://support.checkpoint.com/results/sk/sk180442)

# sk180442 - Firewall log generated by Spark Firewall shows multiple interface names for traffic from the same host

| Property | Value |
|----------|-------|
| Solution ID | sk180442 |
| Date Created | 2023-02-13 |
| Last Modified | 2023-02-26 |
| Technical Level | Advanced |
| Products | Spark Firewall (Locally Managed) |
| Versions | R82.00.X, R81.10.X |

## Symptoms

- * The firewall log generated by the Quantum Spark Appliance shows multiple interface names for traffic from the same host.  
  ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk180442/wrong_interface_name202212231706081.png)  

* The problematic firewall log may also show the wrong rule name.

* Traffic captures via `fw monitor` and `tcpdump` show that the incoming interface name is correct.

* If you follow the procedure in [sk138032](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk138032) to enable the raw log, you see that the problematic firewall log has multiple log updates.

## Cause

The Quantum Spark appliance generates firewall logs with same luuid for different connections, resulting in incorrect log unification.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
