Troubleshooting
Policy
Q: I cannot add ICS applications to my policy by dragging them to the Application column.
A: Make sure is enabled on your policy layer:
- In R80 SmartConsole, go to the view.
- In the section, right-click and select .
The window opens.
- Make sure that is selected.
- In the section, double-click .
- In the window that opens, select .
- Click .
- Click .
- Install the policy.
Logs
Q: I can only see one log for an ICS application, although I sent multiple commands:
A: Make sure your policy contains in the track column.
Q: I cannot see Application Control logs at all, although I can see Firewall logs or traffic of ICS protocols using Wireshark.
A: Check the following:
- Make sure that the Application Control Blade is enabled.
- Update the signature data base of application control to the latest version available.
- Make sure the license for Application Control is valid.
- On Small and Medium Appliances (SMB) - If your ICS traffic is from one Internal interface to another Internal interface or from an Internal interface to the DMZ interface, you need to activate traffic inspection on internal traffic. Refer to the instructions in sk102296.