<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cluster uses VIP to communicate with syslog server in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-uses-VIP-to-communicate-with-syslog-server/m-p/179379#M32866</link>
    <description>&lt;P&gt;Were you able to resolve this issue with these SK's?&lt;/P&gt;</description>
    <pubDate>Thu, 27 Apr 2023 18:36:38 GMT</pubDate>
    <dc:creator>Gzayas</dc:creator>
    <dc:date>2023-04-27T18:36:38Z</dc:date>
    <item>
      <title>Cluster uses VIP to communicate with syslog server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-uses-VIP-to-communicate-with-syslog-server/m-p/141138#M21773</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We have 9 gateways (3 clusters of 3 members each) and we have configured all of them to send syslog to 3rd party log server.&lt;/P&gt;&lt;P&gt;6 devices (2 of the clusters) are sending their syslog properly, one machine at a time.&lt;/P&gt;&lt;P&gt;The last 3 gateways are using the cluster VIP to send syslog data and this is not desired.&lt;/P&gt;&lt;P&gt;There is no NAT employed in this scenario, all this traffic is internal.&lt;/P&gt;&lt;P&gt;Any ideas or tips why this is happening or how we could work around it?&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Andreas.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 11:12:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-uses-VIP-to-communicate-with-syslog-server/m-p/141138#M21773</guid>
      <dc:creator>AndreasD</dc:creator>
      <dc:date>2022-02-10T11:12:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster uses VIP to communicate with syslog server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-uses-VIP-to-communicate-with-syslog-server/m-p/141172#M21782</link>
      <description>&lt;P&gt;Are the clusters all the same version?&lt;/P&gt;
&lt;P&gt;Review&amp;nbsp;sk31832 / sk34180 and compare the settings for each cluster.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 15:10:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-uses-VIP-to-communicate-with-syslog-server/m-p/141172#M21782</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-02-10T15:10:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster uses VIP to communicate with syslog server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-uses-VIP-to-communicate-with-syslog-server/m-p/141175#M21783</link>
      <description>&lt;P&gt;One working cluster is R80.40 not latest JHF. The other working cluster is R81 latest JHF.&lt;/P&gt;&lt;P&gt;The non-working cluster is also R81 latest JHF.&lt;/P&gt;&lt;P&gt;All the clusters are managed by the same management server (R81 latest JHF).&lt;/P&gt;&lt;P&gt;Went through&amp;nbsp;&lt;SPAN&gt;sk31832, checked the table.def on the management server (cat $FWDIR/lib/table.def | grep&amp;nbsp;no_hide_services_ports).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;no_hide_services_ports = { &amp;lt;4500,17&amp;gt;, &amp;lt;500, 17&amp;gt;, &amp;lt;259, 17&amp;gt;, &amp;lt;1701, 17&amp;gt;, &amp;lt;5500, 17&amp;gt;};&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I would modify table.def on management to reflect the below for syslog traffic:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;no_hide_services_ports = { &amp;lt;4500,17&amp;gt;, &amp;lt;500, 17&amp;gt;, &amp;lt;259, 17&amp;gt;, &amp;lt;1701, 17&amp;gt;, &amp;lt;5500, 17&amp;gt;, &amp;lt;514,17&amp;gt;};&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;but I would rather not to since the other two clusters are working.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I will investigate more tomorrow and if I have any update I will post here.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 15:47:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-uses-VIP-to-communicate-with-syslog-server/m-p/141175#M21783</guid>
      <dc:creator>AndreasD</dc:creator>
      <dc:date>2022-02-10T15:47:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster uses VIP to communicate with syslog server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-uses-VIP-to-communicate-with-syslog-server/m-p/179379#M32866</link>
      <description>&lt;P&gt;Were you able to resolve this issue with these SK's?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2023 18:36:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-uses-VIP-to-communicate-with-syslog-server/m-p/179379#M32866</guid>
      <dc:creator>Gzayas</dc:creator>
      <dc:date>2023-04-27T18:36:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster uses VIP to communicate with syslog server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-uses-VIP-to-communicate-with-syslog-server/m-p/179396#M32868</link>
      <description>&lt;P&gt;&lt;A href="https://namitguy.blogspot.com/2020/01/check-point-standby-cluster-member.html" target="_self"&gt;I've done NAT rules in the past&lt;/A&gt; to work around similar issues in the past - no idea if it's the best or recommended way but it does work.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2023 06:18:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-uses-VIP-to-communicate-with-syslog-server/m-p/179396#M32868</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2023-04-28T06:18:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster uses VIP to communicate with syslog server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-uses-VIP-to-communicate-with-syslog-server/m-p/179432#M32869</link>
      <description>&lt;P&gt;I haven't looked into the issue again but have upgraded the specific cluster to R81.10 latest JHF a few weeks ago.&lt;/P&gt;&lt;P&gt;From what I observed today, this behavior has been eliminated and the issue is not occurring.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2023 14:44:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-uses-VIP-to-communicate-with-syslog-server/m-p/179432#M32869</guid>
      <dc:creator>AndreasD</dc:creator>
      <dc:date>2023-04-28T14:44:04Z</dc:date>
    </item>
  </channel>
</rss>

