<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cloudguard controller debug guides in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-controller-debug-guides/m-p/176471#M533</link>
    <description>&lt;P&gt;After editing vsec.conf you need to run "vsec stop; vsec start" .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Right above the Azure errors there should also be Python errors. What they say?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In CloudGuard Controller atrg sk there is a command line how to run the Azure scanning code directly. Please try it, what is the error that you get?&lt;/P&gt;</description>
    <pubDate>Tue, 28 Mar 2023 18:05:24 GMT</pubDate>
    <dc:creator>Gil_Sudai</dc:creator>
    <dc:date>2023-03-28T18:05:24Z</dc:date>
    <item>
      <title>Cloudguard controller debug guides</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-controller-debug-guides/m-p/176433#M527</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Does anyone have any description for the cloudguard debug option? I haven't been able to find any sk on this.&lt;/P&gt;&lt;P&gt;Its the debug option for troubleshooting Cloudguard Controller which connect to Azure as Datacenter objects.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cloudguard controller" style="width: 430px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20267iFA0BA0AAFACEB50A/image-size/large?v=v2&amp;amp;px=999" role="button" title="cloudguard_command_output1812300041.png" alt="Cloudguard controller" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Cloudguard controller&lt;/span&gt;&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what kind of debug are being logged with the "cloudguard debug on" vs. "cloudguard debug full" and where can one find the debug logs?&lt;/P&gt;&lt;P&gt;Looking forward to hear your answers.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Kim&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 12:40:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-controller-debug-guides/m-p/176433#M527</guid>
      <dc:creator>Moberg</dc:creator>
      <dc:date>2023-03-28T12:40:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard controller debug guides</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-controller-debug-guides/m-p/176434#M528</link>
      <description>&lt;P&gt;Have you looked at&amp;nbsp;&lt;SPAN&gt;sk115657&amp;nbsp;&lt;/SPAN&gt;ATRG: CloudGuard Controller?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk115657" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk115657&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 12:53:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-controller-debug-guides/m-p/176434#M528</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2023-03-28T12:53:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard controller debug guides</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-controller-debug-guides/m-p/176435#M529</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/2376"&gt;@Tal_Ron&lt;/a&gt;&amp;nbsp;yes I have and it doesn't explain how it worked.&lt;/P&gt;&lt;P&gt;I have used it a lot the last couple of weeks with TAC and nothing really useful output from them.&lt;/P&gt;&lt;P&gt;I have seen the debug feature but I don't know were to look for the debug information.&lt;/P&gt;&lt;P&gt;The sk should include more information in regards to cloudguard debug controller feature etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 12:55:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-controller-debug-guides/m-p/176435#M529</guid>
      <dc:creator>Moberg</dc:creator>
      <dc:date>2023-03-28T12:55:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard controller debug guides</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-controller-debug-guides/m-p/176441#M530</link>
      <description>&lt;P&gt;I cannot read sk136352 - Common Azure HTML API Error codes in Azure CloudGuard or CloudGuard Controller logs&lt;/P&gt;&lt;P&gt;Could it be this one you think of?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 13:36:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-controller-debug-guides/m-p/176441#M530</guid>
      <dc:creator>Moberg</dc:creator>
      <dc:date>2023-03-28T13:36:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard controller debug guides</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-controller-debug-guides/m-p/176464#M531</link>
      <description>&lt;P&gt;We have retired the debug on and debug full options as they generate too much noise.&lt;/P&gt;
&lt;P&gt;You can enable debug for specific parts of the product in $VSECDIR/lib/log4j.properties (or .xml) file.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Depends on what you want to debug, change the lines from error to debug or trace.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The output is in $FWDIR/log/cloud_proxy.elg file.&lt;/P&gt;
&lt;P&gt;What is the issue you need to debug?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 16:38:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-controller-debug-guides/m-p/176464#M531</guid>
      <dc:creator>Gil_Sudai</dc:creator>
      <dc:date>2023-03-28T16:38:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard controller debug guides</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-controller-debug-guides/m-p/176469#M532</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7211"&gt;@Gil_Sudai&lt;/a&gt;&amp;nbsp;I am having two issues. CMA is not able to automatically fetch dynamic objects from Azure and when I want to import new Azure Objects in SmartConsole I am getting a blank dialog without any objects. After a while I am getting the error message &lt;SPAN&gt;"The Data Center is still initializing, it may take a moment. Please try again later."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;As a work around I can from SmartConsole "&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Objects started getting imported from Azure after performing an "Install database" on the management server.&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;The DC Scanner should fetch this automatically.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We have adjusted the&amp;nbsp;azure.connectTimeoutInMilliseconds=60000 to: azure.connectTimeoutInMilliseconds=6000000 in the file $FWDIR/conf/vsec.conf - which didn't help.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I have been following this ARTG :: Cloudguard guide&amp;nbsp;&lt;SPAN&gt;sk115657 which show no error while troubleshooting.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I still get the following error in cloud_proxy.elg&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[Expert@mgmt:0]# tail -f cloud_proxy.elg&lt;BR /&gt;com.checkpoint.datacenter.util.exception.UnknownProblemException: &lt;STRONG&gt;Failed querying Azure, unknown problem&lt;/STRONG&gt;&lt;BR /&gt;at com.checkpoint.datacenter.scanner.azure.AzureDeployment.getAzureResponse(AzureDeployment.java:223)&lt;BR /&gt;at com.checkpoint.datacenter.scanner.azure.AzureScanner.innerRun(AzureScanner.java:135)&lt;BR /&gt;at com.checkpoint.datacenter.scanner.DcScanner.run(DcScanner.java:120)&lt;BR /&gt;at java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:522)&lt;BR /&gt;at java.util.concurrent.FutureTask.run(FutureTask.java:277)&lt;BR /&gt;at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1160)&lt;BR /&gt;at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:635)&lt;BR /&gt;at java.lang.Thread.run(Thread.java:820)&lt;BR /&gt;16/03/23 09:39:14,490 &lt;STRONG&gt;ERROR datacenter.scanner.DcScanner [scanner-Azure-207686665]: Mapping of Data Center Azure [Application id xxxxxx, directory id xxxxxx] failed&lt;/STRONG&gt; . Next mapping is in 300 seconds.&lt;BR /&gt;^C&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am getting another issue also found in cloud_proxy.elg&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;20/03/23 13:09:23,598 ERROR enforcement.amon.AmonRequestGwsStatusManager [amon-request-sender:30012]: &lt;STRONG&gt;Failed to send Amon request to FWM port 30012&lt;/STRONG&gt;&lt;BR /&gt;javax.xml.ws.WebServiceException: Could not send Message.&lt;BR /&gt;at org.apache.cxf.jaxws.JaxWsClientProxy.invoke(JaxWsClientProxy.java:150)&lt;BR /&gt;at com.sun.proxy.$Proxy54.getAndUpdate(Unknown Source)&lt;BR /&gt;at com.checkpoint.datacenter.enforcement.amon.AmonRequestGwsStatusManager.sendAmonRequest(AmonRequestGwsStatusManager.java:28)&lt;BR /&gt;at com.checkpoint.datacenter.enforcement.amon.AmonRequestGwsStatusManager.access$100(AmonRequestGwsStatusManager.java:37)&lt;BR /&gt;at com.checkpoint.datacenter.enforcement.amon.AmonRequestGwsStatusManager$AmonRequestRunner.run(AmonRequestGwsStatusManager.java:12)&lt;BR /&gt;at java.lang.Thread.run(Thread.java:820)&lt;BR /&gt;Caused by: java.net.ConnectException: ConnectException invoking &lt;A href="https://localhost:30012/amonstatus_service" target="_blank"&gt;https://localhost:30012/amonstatus_service&lt;/A&gt;: Connection refused (Connection refused)&lt;BR /&gt;at sun.reflect.NativeConstructorAccessorImpl.newInstance0(Native Method)&lt;BR /&gt;at sun.reflect.NativeConstructorAccessorImpl.newInstance(NativeConstructorAccessorImpl.java:83)&lt;BR /&gt;at sun.reflect.DelegatingConstructorAccessorImpl.newInstance(DelegatingConstructorAccessorImpl.java:57)&lt;BR /&gt;at java.lang.reflect.Constructor.newInstance(Constructor.java:437)&lt;BR /&gt;at org.apache.cxf.transport.http.HTTPConduit$WrappedOutputStream.mapException(HTTPConduit.java:1365)&lt;BR /&gt;at org.apache.cxf.transport.http.HTTPConduit$WrappedOutputStream.close(HTTPConduit.java:1349)&lt;BR /&gt;at org.apache.cxf.transport.AbstractConduit.close(AbstractConduit.java:56)&lt;BR /&gt;at org.apache.cxf.transport.http.HTTPConduit.close(HTTPConduit.java:652)&lt;BR /&gt;at org.apache.cxf.interceptor.MessageSenderInterceptor$MessageSenderEndingInterceptor.handleMessage(MessageSenderInterceptor.java:62)&lt;BR /&gt;at org.apache.cxf.phase.PhaseInterceptorChain.doIntercept(PhaseInterceptorChain.java:307)&lt;BR /&gt;at org.apache.cxf.endpoint.ClientImpl.doInvoke(ClientImpl.java:516)&lt;BR /&gt;at org.apache.cxf.endpoint.ClientImpl.invoke(ClientImpl.java:425)&lt;BR /&gt;at org.apache.cxf.endpoint.ClientImpl.invoke(ClientImpl.java:326)&lt;BR /&gt;at org.apache.cxf.endpoint.ClientImpl.invoke(ClientImpl.java:279)&lt;BR /&gt;at org.apache.cxf.frontend.ClientProxy.invokeSync(ClientProxy.java:96)&lt;BR /&gt;at org.apache.cxf.jaxws.JaxWsClientProxy.invoke(JaxWsClientProxy.java:139)&lt;BR /&gt;... 5 more&lt;BR /&gt;Caused by: java.net.ConnectException: Connection refused (Connection refused)&lt;BR /&gt;at java.net.AbstractPlainSocketImpl.doConnect(AbstractPlainSocketImpl.java:380)&lt;BR /&gt;at java.net.AbstractPlainSocketImpl.connectToAddress(AbstractPlainSocketImpl.java:236)&lt;BR /&gt;at java.net.AbstractPlainSocketImpl.connect(AbstractPlainSocketImpl.java:218)&lt;BR /&gt;at java.net.SocksSocketImpl.connect(SocksSocketImpl.java:403)&lt;BR /&gt;at java.net.Socket.connect(Socket.java:682)&lt;BR /&gt;at com.ibm.jsse2.av.connect(av.java:694)&lt;BR /&gt;at sun.net.NetworkClient.doConnect(NetworkClient.java:187)&lt;BR /&gt;at sun.net.&lt;A href="http://www.http.HttpClient.openServer(HttpClient.java:494" target="_blank"&gt;www.http.HttpClient.openServer(HttpClient.java:494&lt;/A&gt;)&lt;BR /&gt;at sun.net.&lt;A href="http://www.http.HttpClient.openServer(HttpClient.java:589" target="_blank"&gt;www.http.HttpClient.openServer(HttpClient.java:589&lt;/A&gt;)&lt;BR /&gt;at com.ibm.net.ssl.&lt;A href="http://www2.protocol.https.c" target="_blank"&gt;www2.protocol.https.c&lt;/A&gt;.&amp;lt;init&amp;gt;(c.java:193)&lt;BR /&gt;at com.ibm.net.ssl.&lt;A href="http://www2.protocol.https.c.a(c.java:204" target="_blank"&gt;www2.protocol.https.c.a(c.java:204&lt;/A&gt;)&lt;BR /&gt;at com.ibm.net.ssl.&lt;A href="http://www2.protocol.https.d.getNewHttpClient(d.java:70" target="_blank"&gt;www2.protocol.https.d.getNewHttpClient(d.java:70&lt;/A&gt;)&lt;BR /&gt;at sun.net.&lt;A href="http://www.protocol.http.HttpURLConnection.plainConnect0(HttpURLConnection.java:1174" target="_blank"&gt;www.protocol.http.HttpURLConnection.plainConnect0(HttpURLConnection.java:1174&lt;/A&gt;)&lt;BR /&gt;at sun.net.&lt;A href="http://www.protocol.http.HttpURLConnection.plainConnect(HttpURLConnection.java:1068" target="_blank"&gt;www.protocol.http.HttpURLConnection.plainConnect(HttpURLConnection.java:1068&lt;/A&gt;)&lt;BR /&gt;at com.ibm.net.ssl.&lt;A href="http://www2.protocol.https.d.connect(d.java:71" target="_blank"&gt;www2.protocol.https.d.connect(d.java:71&lt;/A&gt;)&lt;BR /&gt;at sun.net.&lt;A href="http://www.protocol.http.HttpURLConnection.getOutputStream0(HttpURLConnection.java:1352" target="_blank"&gt;www.protocol.http.HttpURLConnection.getOutputStream0(HttpURLConnection.java:1352&lt;/A&gt;)&lt;BR /&gt;at sun.net.&lt;A href="http://www.protocol.http.HttpURLConnection.getOutputStream(HttpURLConnection.java:1327" target="_blank"&gt;www.protocol.http.HttpURLConnection.getOutputStream(HttpURLConnection.java:1327&lt;/A&gt;)&lt;BR /&gt;at com.ibm.net.ssl.&lt;A href="http://www2.protocol.https.b.getOutputStream(b.java:82" target="_blank"&gt;www2.protocol.https.b.getOutputStream(b.java:82&lt;/A&gt;)&lt;BR /&gt;at org.apache.cxf.transport.http.URLConnectionHTTPConduit$URLConnectionWrappedOutputStream.setupWrappedStream(URLConnectionHTTPConduit.java:183)&lt;BR /&gt;at org.apache.cxf.transport.http.HTTPConduit$WrappedOutputStream.handleHeadersTrustCaching(HTTPConduit.java:1308)&lt;BR /&gt;at org.apache.cxf.transport.http.HTTPConduit$WrappedOutputStream.onFirstWrite(HTTPConduit.java:1268)&lt;BR /&gt;at org.apache.cxf.transport.http.URLConnectionHTTPConduit$URLConnectionWrappedOutputStream.onFirstWrite(URLConnectionHTTPConduit.java:210)&lt;BR /&gt;at org.apache.cxf.io.AbstractWrappedOutputStream.write(AbstractWrappedOutputStream.java:47)&lt;BR /&gt;at org.apache.cxf.io.AbstractThresholdOutputStream.write(AbstractThresholdOutputStream.java:69)&lt;BR /&gt;at org.apache.cxf.transport.http.HTTPConduit$WrappedOutputStream.close(HTTPConduit.java:1321)&lt;BR /&gt;... 15 more&lt;BR /&gt;[Expert@mgmt:0]#&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the following issue which was found while looking into cloud_proxy.elg&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 17:55:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-controller-debug-guides/m-p/176469#M532</guid>
      <dc:creator>Moberg</dc:creator>
      <dc:date>2023-03-28T17:55:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard controller debug guides</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-controller-debug-guides/m-p/176471#M533</link>
      <description>&lt;P&gt;After editing vsec.conf you need to run "vsec stop; vsec start" .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Right above the Azure errors there should also be Python errors. What they say?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In CloudGuard Controller atrg sk there is a command line how to run the Azure scanning code directly. Please try it, what is the error that you get?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 18:05:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-controller-debug-guides/m-p/176471#M533</guid>
      <dc:creator>Gil_Sudai</dc:creator>
      <dc:date>2023-03-28T18:05:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard controller debug guides</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-controller-debug-guides/m-p/176474#M534</link>
      <description>&lt;P&gt;Sorry, yes I did restart the service with “&lt;SPAN&gt;vsec stop; vsec start" and wanted 30 minutes because the DC scanner runs every 30 minutes.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I had to quickly extract the information from the logs. I can send you the SR ticket no if you can acces that?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 18:12:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-controller-debug-guides/m-p/176474#M534</guid>
      <dc:creator>Kim_Moberg</dc:creator>
      <dc:date>2023-03-28T18:12:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard controller debug guides</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-controller-debug-guides/m-p/176477#M535</link>
      <description>&lt;P&gt;Please ask ask our support engineer that handle the SR to contact me or my team.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 18:24:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-controller-debug-guides/m-p/176477#M535</guid>
      <dc:creator>Gil_Sudai</dc:creator>
      <dc:date>2023-03-28T18:24:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard controller debug guides</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-controller-debug-guides/m-p/176486#M537</link>
      <description>&lt;P&gt;On Checkmates with wrong account.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks. I have updated the your support engineer to reach out to you or your team.&lt;/P&gt;&lt;P&gt;I am missing some better way of troubleshooting the Cloudguard controller. The ARTG Cloudguard Controller guide does provide some initial guidance.&lt;/P&gt;&lt;P&gt;the Azure debug query did curl and fetch Azure objects without any isssues (no errors) and still the cloud_proxy.elg drops an error stack exception and TAC support was searching in east and west which in my eyes are not related to the issue.&lt;/P&gt;&lt;P&gt;Just seaching for cloud_proxy.elg in support center doesnt provide any hints at all.&lt;/P&gt;&lt;P&gt;If you would like to have feedback on this please dont hesitate to reach out to me. I’ve have been working close with RnD Team managers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 19:31:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-controller-debug-guides/m-p/176486#M537</guid>
      <dc:creator>Moberg</dc:creator>
      <dc:date>2023-03-28T19:31:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard controller debug guides</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-controller-debug-guides/m-p/176519#M538</link>
      <description>&lt;P&gt;This is the whole error exception found in cloud_proxy.elg&lt;BR /&gt;&lt;BR /&gt;23/03/23 09:48:05,775 ERROR util.process.ProcessExecutor [scanner-Azure-2065078223]: java.util.concurrent.TimeoutException&lt;BR /&gt;23/03/23 09:48:05,775 ERROR util.process.ProcessExecutor [scanner-Azure-2065078223]: Timeout reached: 1200 seconds, killing process&lt;BR /&gt;23/03/23 09:48:05,776 ERROR util.process.ProcessExecutor [pool-2136-thread-1]: protectedWait: java.lang.InterruptedException&lt;BR /&gt;23/03/23 09:48:06,118 ERROR util.process.ProcessExecutor [Thread-235]: ProcessStreamReader: stderr - run: java.io.IOException: Stream closed&lt;BR /&gt;23/03/23 09:48:06,120 ERROR scanner.azure.AzureDeployment [scanner-Azure-2065078223]: com.checkpoint.datacenter.util.exception.ProcessExecutionException: Failed running process&lt;BR /&gt;23/03/23 09:48:06,120 ERROR datacenter.scanner.DcScanner [scanner-Azure-2065078223]: Error during scan - attempting to reconnect for scanner Azure [Application id xxxxxx, directory id xxxxxx]&lt;BR /&gt;com.checkpoint.datacenter.util.exception.UnknownProblemException: Failed querying Azure, unknown problem&lt;BR /&gt;at com.checkpoint.datacenter.scanner.azure.AzureDeployment.getAzureResponse(AzureDeployment.java:223)&lt;BR /&gt;at com.checkpoint.datacenter.scanner.azure.AzureScanner.innerRun(AzureScanner.java:135)&lt;BR /&gt;at com.checkpoint.datacenter.scanner.DcScanner.run(DcScanner.java:120)&lt;BR /&gt;at java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:522)&lt;BR /&gt;at java.util.concurrent.FutureTask.run(FutureTask.java:277)&lt;BR /&gt;at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1160)&lt;BR /&gt;at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:635)&lt;BR /&gt;at java.lang.Thread.run(Thread.java:820)&lt;BR /&gt;23/03/23 09:48:06,121 ERROR scanner.util.DcScannerUtils [scanner-Azure-2065078223]: Exception while connecting to Azure [Application id xxxxxx, directory id xxxxx]. Return unknown problem.&lt;BR /&gt;com.checkpoint.datacenter.util.exception.UnknownProblemException: Failed querying Azure, unknown problem&lt;BR /&gt;at com.checkpoint.datacenter.scanner.azure.AzureDeployment.getAzureResponse(AzureDeployment.java:223)&lt;BR /&gt;at com.checkpoint.datacenter.scanner.azure.AzureScanner.innerRun(AzureScanner.java:135)&lt;BR /&gt;at com.checkpoint.datacenter.scanner.DcScanner.run(DcScanner.java:120)&lt;BR /&gt;at java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:522)&lt;BR /&gt;at java.util.concurrent.FutureTask.run(FutureTask.java:277)&lt;BR /&gt;at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1160)&lt;BR /&gt;at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:635)&lt;BR /&gt;at java.lang.Thread.run(Thread.java:820)&lt;BR /&gt;23/03/23 09:48:06,121 ERROR datacenter.scanner.DcScanner [scanner-Azure-2065078223]: Mapping of Data Center Azure [Application id xxxxxx, directory id xxxxxx] failed . Next mapping is in 300 seconds.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2023 06:33:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-controller-debug-guides/m-p/176519#M538</guid>
      <dc:creator>Moberg</dc:creator>
      <dc:date>2023-03-29T06:33:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard controller debug guides</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-controller-debug-guides/m-p/176619#M539</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7211"&gt;@Gil_Sudai&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have been working on the troubleshooting editing the specific parts of the&amp;nbsp;&lt;SPAN&gt;the product in $VSECDIR/lib/log4j.properties (or .xml) file.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Does all of the parts support ERROR, DEBUG and TRACE or is it just some of the&amp;nbsp;pecific parts of the&amp;nbsp;the product in $VSECDIR/lib/log4j.properties&amp;nbsp; only support ERROR and DEBUG but not TRACE?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What are the time frame for the change in $VSECDIR/lib/log4j.properties to take effect to be shown in&amp;nbsp;&amp;nbsp;$FWDIR/log/cloud_proxy.elg file?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Do I need to&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;run "vsec stop; vsec start" after every change?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;BR&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Kim&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2023 15:35:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-controller-debug-guides/m-p/176619#M539</guid>
      <dc:creator>Kim_Moberg</dc:creator>
      <dc:date>2023-03-29T15:35:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard controller debug guides</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-controller-debug-guides/m-p/177000#M540</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;
&lt;P&gt;All parts support trace &amp;gt; debug &amp;gt; info &amp;gt; error.&lt;/P&gt;
&lt;P&gt;According to the data you sent:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;23/03/23 09:48:05,775 ERROR util.process.ProcessExecutor [scanner-Azure-2065078223]: Timeout reached: 1200 seconds, killing process&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;It looks like the Azure scanning take longer than 1200 seconds. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Can you confirm that by running the vsec.py command line manually and checking how much time it takes? You can use 'date' and such.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I suggest that you edit vsec.conf and change entry (or add if missing)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;azure.connectTimeoutInMilliseconds&lt;/P&gt;
&lt;P&gt;to high value. For example:&lt;/P&gt;
&lt;P&gt;azure.connectTimeoutInMilliseconds=5000000&lt;/P&gt;
&lt;P&gt;Then run "vsec stop;vsec start" to restart the CloudGuard Controller process.&lt;/P&gt;
&lt;P&gt;Does it helps?&lt;/P&gt;</description>
      <pubDate>Sun, 02 Apr 2023 06:38:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-controller-debug-guides/m-p/177000#M540</guid>
      <dc:creator>Gil_Sudai</dc:creator>
      <dc:date>2023-04-02T06:38:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard controller debug guides</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-controller-debug-guides/m-p/177088#M541</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7211"&gt;@Gil_Sudai&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thats true the raising the value of&amp;nbsp;&lt;SPAN&gt;azure.connectTimeoutInMilliseconds&lt;/SPAN&gt;&amp;nbsp;in $FWDIR/conf/vsec.conf solved the timeout. Though the values 5000000 is too high and the system cannot figure how it should be handled. I lowered the value to 600000 and that seems to have solve the issue in cloud_proxy.elg "Timeout reached: 1200 seconds, killing process"&lt;/P&gt;&lt;P&gt;How is it with the&amp;nbsp; function RequestGwsStatusManager- how does that function work?&lt;BR /&gt;&lt;BR /&gt;enforcement.amon.AmonRequestGwsStatusManager [amon-request-sender:30012]: Failed to send Amon request to FWM port 30012&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I do tcpdump on mgmt and open another ssh session to same host. If I do "telnet 127.0.0.1 30012" I then see connection closed and output of the tcpdump dump. If I keep the tcpdump running I get multiple tries which matches the date/time from cloud_proxy.elg.&lt;/P&gt;&lt;P&gt;RequestGwsStatusManager does this search for a secure gateway and it is blocked or not responding or how is it?&lt;/P&gt;&lt;P&gt;Br&lt;/P&gt;&lt;P&gt;Kim&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2023 06:55:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-controller-debug-guides/m-p/177088#M541</guid>
      <dc:creator>Kim_Moberg</dc:creator>
      <dc:date>2023-04-03T06:55:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard controller debug guides</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-controller-debug-guides/m-p/177116#M542</link>
      <description>&lt;P&gt;try to restart the FWM app. Did it fix it?&amp;nbsp; You can use the "cpwd_admin" command on the mgmt for that and there are also usage examples if you just run "cpwd_admin"&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2023 10:00:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-controller-debug-guides/m-p/177116#M542</guid>
      <dc:creator>Gil_Sudai</dc:creator>
      <dc:date>2023-04-03T10:00:24Z</dc:date>
    </item>
  </channel>
</rss>

