<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Traffic Logs post-migration in Portal</title>
    <link>https://community.checkpoint.com/t5/Portal/Traffic-Logs-post-migration/m-p/224622#M366</link>
    <description>&lt;P&gt;Just a thought, try installing the database to all servers, and check if the log server's SIC is up&lt;/P&gt;</description>
    <pubDate>Tue, 27 Aug 2024 10:20:57 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2024-08-27T10:20:57Z</dc:date>
    <item>
      <title>Traffic Logs post-migration</title>
      <link>https://community.checkpoint.com/t5/Portal/Traffic-Logs-post-migration/m-p/224620#M365</link>
      <description>&lt;P&gt;Hi Checkmates,&lt;/P&gt;&lt;P&gt;My first post. Be gentle &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I inherited an R80.40 (Take 211) Cloudguard Network Security environment in Azure (HA deployment). We have migrated the management to Smart-1 Cloud as part of our DR improvement and upgrade project for this environment.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The migration went well (so management is now R81.20) but we now have no traffic logs. MaaS tunnel is up, we can push policy,&amp;nbsp; but log server shows disconnected:&lt;/P&gt;&lt;P&gt;Log Servers Connections&lt;BR /&gt;---------------------------------------------------------&lt;BR /&gt;|IP |Status|Status Description |Sending Rate|&lt;BR /&gt;---------------------------------------------------------&lt;BR /&gt;|100.64.0.52| 1|Log-Server Disconnected| 0|&lt;BR /&gt;---------------------------------------------------------&lt;/P&gt;&lt;P&gt;[Expert@GW_1:]# cat /etc/fw/conf/masters&lt;BR /&gt;[Policy]&lt;BR /&gt;NAME&lt;BR /&gt;[Log]&lt;BR /&gt;NAME&lt;BR /&gt;[Alert]&lt;BR /&gt;NAME&lt;/P&gt;&lt;P&gt;(where NAME is the name of the management server object with standard IP of 100.64.0.52).&lt;/P&gt;&lt;P&gt;Does anyone know how to get the Log Server&amp;nbsp; connected?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 10:21:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Traffic-Logs-post-migration/m-p/224620#M365</guid>
      <dc:creator>wanartisan</dc:creator>
      <dc:date>2024-08-27T10:21:19Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic Logs post-migration</title>
      <link>https://community.checkpoint.com/t5/Portal/Traffic-Logs-post-migration/m-p/224622#M366</link>
      <description>&lt;P&gt;Just a thought, try installing the database to all servers, and check if the log server's SIC is up&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 10:20:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Traffic-Logs-post-migration/m-p/224622#M366</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-08-27T10:20:57Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic Logs post-migration</title>
      <link>https://community.checkpoint.com/t5/Portal/Traffic-Logs-post-migration/m-p/224623#M367</link>
      <description>&lt;P&gt;I'm sure I did that. I was following&amp;nbsp;sk38848. Also checked masters file is not immutable.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The log server is the Smart-1 Cloud so SIC is working.&amp;nbsp;&lt;/P&gt;&lt;P&gt;None of the connectivity tests work from that sk. But there is a route&lt;/P&gt;&lt;P&gt;100.64.0.0 * 255.255.255.0 U 0 0 0 maas_tunnel&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 10:31:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Traffic-Logs-post-migration/m-p/224623#M367</guid>
      <dc:creator>wanartisan</dc:creator>
      <dc:date>2024-08-27T10:31:58Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic Logs post-migration</title>
      <link>https://community.checkpoint.com/t5/Portal/Traffic-Logs-post-migration/m-p/224629#M368</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/110029"&gt;@wanartisan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What does the #cpstat mg -f log_server say?&lt;/P&gt;
&lt;P&gt;The main IP of the SmartCenter changed?&lt;/P&gt;
&lt;P&gt;Last time, I ran into almost the same issue. In that scenario the SmartCenter was on-prem, and the GW-s were in Cloud, The GW-s send the logs to&amp;nbsp; the wrong IP, the main IP of the smartCenter was unreachable for them. (because of routing and security issues)&lt;/P&gt;
&lt;P&gt;We changed the LOG IP in masters file on the&amp;nbsp; GWs, according to this articles:&lt;/P&gt;
&lt;P&gt;&lt;A style="font-family: inherit; background-color: #ffffff;" href="https://support.checkpoint.com/results/sk/sk40090" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk40090&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk105280" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk105280&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and a few related articles:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk146112" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk146112&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk102712" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk102712&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I hope it helps,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 12:20:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Traffic-Logs-post-migration/m-p/224629#M368</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-08-27T12:20:52Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic Logs post-migration</title>
      <link>https://community.checkpoint.com/t5/Portal/Traffic-Logs-post-migration/m-p/224635#M369</link>
      <description>&lt;P&gt;[Expert@GW1:0]# cpstat mg -f log_server&lt;BR /&gt;No product has flag 'mg'&lt;/P&gt;&lt;P&gt;Yes, the log server IP has changed to 100.64.0.52 which is the same IP Smart-1 Cloud always uses for the management object. In cplog_debug.elg you can see the migration script changes the IP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[9611 3981629376]fwd@GW1[Thu Aug 15 20:55:12 2024] ResetLogServers: The ip of [MGMT_NAME] was changed, the old ip is [OLD IP], the new ip is 100.64.0.52&lt;/P&gt;&lt;P&gt;The log also shows connectivity good to the old IP then connectivity failing to the new IP.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 12:30:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Traffic-Logs-post-migration/m-p/224635#M369</guid>
      <dc:creator>wanartisan</dc:creator>
      <dc:date>2024-08-27T12:30:46Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic Logs post-migration</title>
      <link>https://community.checkpoint.com/t5/Portal/Traffic-Logs-post-migration/m-p/224637#M370</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/110029"&gt;@wanartisan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sorry, de correct syntax for LOG servers is this:&amp;nbsp;&lt;SPAN&gt;cpstat ls&amp;nbsp; -f logging&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Try to edit the MASTERS file, check this&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk105280" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk105280&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;PART 2:&amp;nbsp;Edit the $FWDIR/conf/masters file to contain the desired IP address of the Log Server&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cheers,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 12:37:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Traffic-Logs-post-migration/m-p/224637#M370</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-08-27T12:37:47Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic Logs post-migration</title>
      <link>https://community.checkpoint.com/t5/Portal/Traffic-Logs-post-migration/m-p/224642#M371</link>
      <description>&lt;P&gt;[Expert@GW1:0]# cpstat ls -f logging&lt;BR /&gt;No product has flag 'ls'&lt;/P&gt;&lt;P&gt;If you see my output above for&amp;nbsp;cat /etc/fw/conf/masters you should see that the log server is set to the management object and that management object has the new IP of 100.64.0.52.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 12:47:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Traffic-Logs-post-migration/m-p/224642#M371</guid>
      <dc:creator>wanartisan</dc:creator>
      <dc:date>2024-08-27T12:47:31Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic Logs post-migration</title>
      <link>https://community.checkpoint.com/t5/Portal/Traffic-Logs-post-migration/m-p/224655#M372</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/110029"&gt;@wanartisan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In this case the NAME means de FQDN of the SmartCenter?&lt;BR /&gt;When I modified the masters file, i used IP insted of FQDN.&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 14:05:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Traffic-Logs-post-migration/m-p/224655#M372</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-08-27T14:05:45Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic Logs post-migration</title>
      <link>https://community.checkpoint.com/t5/Portal/Traffic-Logs-post-migration/m-p/224662#M373</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Yes NAME = the name of the object in SmartConsole (with IP 100.64.0.52).&lt;/P&gt;&lt;P&gt;I am a bit sceptical this change will help if the IP connectivity tests to the LogServer (Samrt-1 Cloud) aren't working.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 14:48:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Traffic-Logs-post-migration/m-p/224662#M373</guid>
      <dc:creator>wanartisan</dc:creator>
      <dc:date>2024-08-27T14:48:43Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic Logs post-migration</title>
      <link>https://community.checkpoint.com/t5/Portal/Traffic-Logs-post-migration/m-p/224664#M374</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/110029"&gt;@wanartisan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, first the connectivity.&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 14:53:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Traffic-Logs-post-migration/m-p/224664#M374</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-08-27T14:53:04Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic Logs post-migration</title>
      <link>https://community.checkpoint.com/t5/Portal/Traffic-Logs-post-migration/m-p/224718#M375</link>
      <description>&lt;P&gt;If connectivity does not work at all, that must be your clue. If you are still struggling with it, I suggest a TAC case.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 06:48:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Traffic-Logs-post-migration/m-p/224718#M375</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-08-28T06:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic Logs post-migration</title>
      <link>https://community.checkpoint.com/t5/Portal/Traffic-Logs-post-migration/m-p/226726#M382</link>
      <description>&lt;P&gt;To close this off, Install Database did work. Not sure why it didn't the first time (I'm sure it was one of the first things I did...)&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Sep 2024 10:56:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Traffic-Logs-post-migration/m-p/226726#M382</guid>
      <dc:creator>wanartisan</dc:creator>
      <dc:date>2024-09-16T10:56:29Z</dc:date>
    </item>
  </channel>
</rss>

