> Source: [sk182130](https://support.checkpoint.com/results/sk/sk182130)

# sk182130 - Logs show accepted when the connection should be dropped

| Property | Value |
|----------|-------|
| Solution ID | sk182130 |
| Date Created | 2024-03-21 |
| Last Modified | 2025-01-16 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R81 (EOS) |

## Symptoms

- * Traffic should be dropped, but SmartLog shows accept logs from Geo Protection.

* In addition to the Geo Protection log, an additional log card can be seen for this connection, showing it was dropped by the Access Control policy.

## Cause

For a connection to be fully accepted, it must be accepted at every layer in the inspection chain. This means that if it is accepted at one layer, it continues to the next. If at any point in these layers the connection matches a drop rule, it stops looking at further layers and drops the connection.

The legacy Geo Protection layer is one of the first things that a connection is checked against, but it is separate from the Unified Policy layer. **This causes it to show as a separate log card**. After traffic is allowed through this layer, the log is generated, and the connection continues inspection against the Access Control policy.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
