> Source: [sk183241](https://support.checkpoint.com/results/sk/sk183241)

# sk183241 - SmartConsole does not show logs or enforcement actions from Custom Intelligence Feeds after upgrade to R81.20

| Property | Value |
|----------|-------|
| Solution ID | sk183241 |
| Date Created | 2025-03-17 |
| Last Modified | 2025-03-18 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |

## Symptoms

- * After upgrading to R81.20, SmartConsole does not display logs or enforcement actions from Custom Intelligence (IoC) Feeds.

* The Security Gateway does not enforce IoC Feeds, even when the configuration appears correct.

* IoC Observables appear in the Denial of Service (DoS) Deny List but do not trigger logs in SmartView or the Security Gateway.

  **Note** : An Observable is an event or a stateful property observed in an operational cyber domain (examples: IP address, MD5 file signature, URL, Mail sender address). For more information about Observables, see [sk132193](https://support.checkpoint.com/results/sk/sk132193).

## Cause

In R81 and lower versions, the DoS Deny List (retrieved by the "`fwaccel dos config get`" command) was disabled by default. Starting from R81.20, this setting is enabled by default on fresh installations.

When upgrading from R81 to R81.20, the previous configuration is preserved. If the Deny List was disabled before the upgrade, it remains disabled unless manually changed.

Additionally, an administrator may have disabled this setting, either intentionally or due to configuration changes. When disabled, IoC Feed enforcement does not generate logs or enforcement actions.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
