<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sending logs from Checkpoint R80.40 to Remote server in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-logs-from-Checkpoint-R80-40-to-Remote-server/m-p/135585#M20451</link>
    <description>&lt;P&gt;Hello,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks for your response.&amp;nbsp;&lt;BR /&gt;I have defined the Syslog server IP address in Hosts and created server with Name, Host IP address and Port Number.&amp;nbsp;&lt;/P&gt;&lt;P&gt;For R80.40, I have added the new Syslog Server to the Security Gateway logging targets - Security Gateway &amp;gt; Logs.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;For some reason, Logs are not received in remote server. Thanks again for your response. Your assist will be of great help to me.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;Muthu Mahadevan&lt;/P&gt;</description>
    <pubDate>Mon, 06 Dec 2021 08:57:27 GMT</pubDate>
    <dc:creator>Mahadevan</dc:creator>
    <dc:date>2021-12-06T08:57:27Z</dc:date>
    <item>
      <title>Sending logs from Checkpoint R80.40 to Remote server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-logs-from-Checkpoint-R80-40-to-Remote-server/m-p/135575#M20446</link>
      <description>&lt;P&gt;Hello all,&lt;BR /&gt;&lt;BR /&gt;I have installed Checkpoint R80.40 in Vmware. I have created Network object and also created syslog server with port number. It is showing in Smartconsole logs that data is accepted from Firewall to Remote server.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I am not receving logs from Checkpoint to Remote server.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please find the attachment. Kindly let me know the changes I have to make to send logs from Checkpoint to remote server. Your assistance will be of great help to me.&lt;BR /&gt;&lt;BR /&gt;REgards&lt;BR /&gt;Muthu Mahadevan&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Dec 2021 07:02:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-logs-from-Checkpoint-R80-40-to-Remote-server/m-p/135575#M20446</guid>
      <dc:creator>Mahadevan</dc:creator>
      <dc:date>2021-12-06T07:02:25Z</dc:date>
    </item>
    <item>
      <title>Re: Sending logs from Checkpoint R80.40 to Remote server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-logs-from-Checkpoint-R80-40-to-Remote-server/m-p/135583#M20449</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just making sure you performed the following steps as well:&lt;/P&gt;
&lt;P&gt;1) Defined the Syslog Server - in Objects Pane &amp;gt; Servers &amp;gt; Syslog&lt;/P&gt;
&lt;P&gt;2) Added the new Syslog Server to the Security Gateway logging targets - Security Gateway &amp;gt; Logs&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Dec 2021 08:08:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-logs-from-Checkpoint-R80-40-to-Remote-server/m-p/135583#M20449</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2021-12-06T08:08:07Z</dc:date>
    </item>
    <item>
      <title>Re: Sending logs from Checkpoint R80.40 to Remote server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-logs-from-Checkpoint-R80-40-to-Remote-server/m-p/135585#M20451</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks for your response.&amp;nbsp;&lt;BR /&gt;I have defined the Syslog server IP address in Hosts and created server with Name, Host IP address and Port Number.&amp;nbsp;&lt;/P&gt;&lt;P&gt;For R80.40, I have added the new Syslog Server to the Security Gateway logging targets - Security Gateway &amp;gt; Logs.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;For some reason, Logs are not received in remote server. Thanks again for your response. Your assist will be of great help to me.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;Muthu Mahadevan&lt;/P&gt;</description>
      <pubDate>Mon, 06 Dec 2021 08:57:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-logs-from-Checkpoint-R80-40-to-Remote-server/m-p/135585#M20451</guid>
      <dc:creator>Mahadevan</dc:creator>
      <dc:date>2021-12-06T08:57:27Z</dc:date>
    </item>
    <item>
      <title>Re: Sending logs from Checkpoint R80.40 to Remote server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-logs-from-Checkpoint-R80-40-to-Remote-server/m-p/135590#M20453</link>
      <description>&lt;P&gt;Also, Just to add the previous comment,&lt;BR /&gt;&lt;BR /&gt;When I check for&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Expert@gw-firewall:0]# fw ctl get int fwsyslog_enable&lt;BR /&gt;&lt;STRONG&gt;fwsyslog_enable = 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;But still Logs are not going to Remote server.&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;Muthu Mahadevan&lt;/P&gt;</description>
      <pubDate>Mon, 06 Dec 2021 09:21:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-logs-from-Checkpoint-R80-40-to-Remote-server/m-p/135590#M20453</guid>
      <dc:creator>Mahadevan</dc:creator>
      <dc:date>2021-12-06T09:21:58Z</dc:date>
    </item>
    <item>
      <title>Re: Sending logs from Checkpoint R80.40 to Remote server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-logs-from-Checkpoint-R80-40-to-Remote-server/m-p/135602#M20454</link>
      <description>&lt;P&gt;Hi Muthu,&lt;/P&gt;
&lt;P&gt;Why not using the Log Exporter?&lt;/P&gt;</description>
      <pubDate>Mon, 06 Dec 2021 10:51:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-logs-from-Checkpoint-R80-40-to-Remote-server/m-p/135602#M20454</guid>
      <dc:creator>Ido_Shoshana</dc:creator>
      <dc:date>2021-12-06T10:51:57Z</dc:date>
    </item>
    <item>
      <title>Re: Sending logs from Checkpoint R80.40 to Remote server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-logs-from-Checkpoint-R80-40-to-Remote-server/m-p/135622#M20459</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have put the below commands -&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;cp_log_export add name to_RemoteServer target-server X.X.X.X target-port 514 protocol udp format syslog&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;cp_log_export restart name to_RemoteServer&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;I am able to see in the log file in Smartconsole that&amp;nbsp;&lt;/P&gt;&lt;P&gt;* Source IP - Firewall&amp;nbsp;&lt;/P&gt;&lt;P&gt;* Destination - Remote server IP&lt;/P&gt;&lt;P&gt;* Service - UDP/port number&lt;/P&gt;&lt;P&gt;* Description - Traffic accepted.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But the logs are not appearing in the remote server. Could you please let me know the changes to make to receive the logs in remote logging ??&lt;/P&gt;&lt;P&gt;Regards&lt;BR /&gt;Muthu Mahadevan&lt;/P&gt;</description>
      <pubDate>Mon, 06 Dec 2021 12:32:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-logs-from-Checkpoint-R80-40-to-Remote-server/m-p/135622#M20459</guid>
      <dc:creator>Mahadevan</dc:creator>
      <dc:date>2021-12-06T12:32:52Z</dc:date>
    </item>
    <item>
      <title>Re: Sending logs from Checkpoint R80.40 to Remote server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-logs-from-Checkpoint-R80-40-to-Remote-server/m-p/135667#M20479</link>
      <description>&lt;P&gt;What we are missing here is any information about the syslog server you are using and the OS it is running on.&lt;/P&gt;
&lt;P&gt;You may have to configure syslog sources from which your server accepts logs and, perhaps, create OS-specific firewall rules allowing inbound traffic on chosen ports.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Dec 2021 20:06:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-logs-from-Checkpoint-R80-40-to-Remote-server/m-p/135667#M20479</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2021-12-06T20:06:19Z</dc:date>
    </item>
    <item>
      <title>Re: Sending logs from Checkpoint R80.40 to Remote server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-logs-from-Checkpoint-R80-40-to-Remote-server/m-p/135688#M20483</link>
      <description>&lt;P&gt;Hello Vladimir,&lt;BR /&gt;&lt;BR /&gt;Thanks for your response. I have Remote Logging server running in Ubuntu (VirtualBox). I have added security policy in SmartConsole with&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Source address - Firewall IP&lt;/P&gt;&lt;P&gt;Destination address - Remote Logging IP address&lt;/P&gt;&lt;P&gt;Action - Accept&lt;/P&gt;&lt;P&gt;Could you please let me know the changes to make if the remote server is running in Ubuntu version ??&lt;/P&gt;&lt;P&gt;Regards&lt;BR /&gt;Muthu Mahadevan&lt;/P&gt;</description>
      <pubDate>Tue, 07 Dec 2021 04:18:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-logs-from-Checkpoint-R80-40-to-Remote-server/m-p/135688#M20483</guid>
      <dc:creator>Mahadevan</dc:creator>
      <dc:date>2021-12-07T04:18:04Z</dc:date>
    </item>
    <item>
      <title>Re: Sending logs from Checkpoint R80.40 to Remote server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-logs-from-Checkpoint-R80-40-to-Remote-server/m-p/135691#M20484</link>
      <description>&lt;P&gt;Firewall will send only Gaia level logs, not the firewall logs. If you have configured log exporter on the &lt;STRONG&gt;management server&lt;/STRONG&gt; as per:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;cp_log_export add name to_RemoteServer target-server X.X.X.X target-port 514 protocol udp format syslog&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;and configured the&lt;/P&gt;
&lt;P&gt;$AllowedSender UDP, 127.0.0.1, Y.Y.Y.Y/YY&lt;/P&gt;
&lt;P&gt;on the Ubuntu side, where Y.Y.Y.Y/YY is the IP and the subnet of the Check Point management server,&lt;/P&gt;
&lt;P&gt;then run:&lt;/P&gt;
&lt;P&gt;tcpdump -vv port 514&lt;/P&gt;
&lt;P&gt;on Ubuntu to see if you are receiving logs from Check Point.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Dec 2021 05:06:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-logs-from-Checkpoint-R80-40-to-Remote-server/m-p/135691#M20484</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2021-12-07T05:06:05Z</dc:date>
    </item>
    <item>
      <title>Re: Sending logs from Checkpoint R80.40 to Remote server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-logs-from-Checkpoint-R80-40-to-Remote-server/m-p/135701#M20486</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;I also wanted to check with you with the below configuration,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Expert@gw-firewall:0]# cp_log_export show&lt;/P&gt;&lt;P&gt;name: CP_FW&lt;BR /&gt;enabled: true&lt;BR /&gt;target-server: 10.0.2.15&lt;BR /&gt;target-port: 1514&lt;BR /&gt;protocol: udp&lt;BR /&gt;format: syslog&lt;BR /&gt;read-mode: raw&lt;BR /&gt;export-link: false&lt;BR /&gt;export-attachment-link: false&lt;/P&gt;&lt;P&gt;Also when I check for the logs in SmartConsole, &lt;STRONG&gt;Source&lt;/STRONG&gt; - Firewall IP, &lt;STRONG&gt;Destination&lt;/STRONG&gt; - Remote Logging IP and &lt;STRONG&gt;Action&lt;/STRONG&gt; - accept.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since the status is showing enabled and Connection action is appearing accept in logs, can I assume the logs are sent from firewall to my remote logging ?? Issue is near remote logging ??&lt;/P&gt;</description>
      <pubDate>Tue, 07 Dec 2021 07:46:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-logs-from-Checkpoint-R80-40-to-Remote-server/m-p/135701#M20486</guid>
      <dc:creator>Mahadevan</dc:creator>
      <dc:date>2021-12-07T07:46:05Z</dc:date>
    </item>
    <item>
      <title>Re: Sending logs from Checkpoint R80.40 to Remote server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-logs-from-Checkpoint-R80-40-to-Remote-server/m-p/135746#M20499</link>
      <description>&lt;P&gt;You can assume that the issue is on the Ubuntu side.&lt;/P&gt;
&lt;P&gt;Also, if information in your last post is correct, on Check Point side you are using UDP port 1514 instead of a standard syslog port UDP 514 where Ubuntu may be expecting this traffic.&lt;/P&gt;
&lt;P&gt;Unless you have changed the default syslog service port on Ubuntu, I suggest changing it back to 514 on Check Point.&lt;/P&gt;
&lt;P&gt;Then use tcpdump on Ubuntu to see if syslog traffic arriving there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Dec 2021 15:55:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-logs-from-Checkpoint-R80-40-to-Remote-server/m-p/135746#M20499</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2021-12-07T15:55:57Z</dc:date>
    </item>
    <item>
      <title>Re: Sending logs from Checkpoint R80.40 to Remote server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-logs-from-Checkpoint-R80-40-to-Remote-server/m-p/135771#M20501</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Thanks for all the Inputs.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Issue was in Ubuntu side and I have set the redirect Configuration to receive input from Firewall.&lt;/P&gt;&lt;P&gt;Regards&lt;BR /&gt;Muthu Mahadevan&lt;/P&gt;</description>
      <pubDate>Wed, 08 Dec 2021 07:51:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-logs-from-Checkpoint-R80-40-to-Remote-server/m-p/135771#M20501</guid>
      <dc:creator>Mahadevan</dc:creator>
      <dc:date>2021-12-08T07:51:43Z</dc:date>
    </item>
  </channel>
</rss>

