<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 81.20 Logging issue after cluster switch in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/81-20-Logging-issue-after-cluster-switch/m-p/242685#M47152</link>
    <description>&lt;P&gt;Thx AkosBakos for your reply.&lt;/P&gt;&lt;P&gt;We are able to reach both nodes from management and viceversa.&lt;/P&gt;&lt;P&gt;Logging is ok until we switch the cluster and node2 becomes active.&lt;/P&gt;&lt;P&gt;As soon the second node becomes active the issue arises&lt;/P&gt;</description>
    <pubDate>Fri, 28 Feb 2025 14:59:28 GMT</pubDate>
    <dc:creator>frenzetti</dc:creator>
    <dc:date>2025-02-28T14:59:28Z</dc:date>
    <item>
      <title>81.20 Logging issue after cluster switch</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/81-20-Logging-issue-after-cluster-switch/m-p/242649#M47133</link>
      <description>&lt;P&gt;Hi mates,&lt;/P&gt;&lt;P&gt;after updating the secure gateway version from 81.20 to 81.20 take 92 we are facing a strange problem on securegateway node&lt;BR /&gt;One of the two cluster nodes sends logs to management only if it is in STANDBY state.&lt;BR /&gt;If it is "promoted" to ACTIVE it stops sending logs to management&lt;/P&gt;&lt;P&gt;This is the output of the cpstat fw -f log_connection command when the node is STANDBY&lt;BR /&gt;Overall Status: 0&lt;BR /&gt;Overall Status Description: Security Gateway is reporting logs as defined&lt;BR /&gt;Local Logging Mode Description: Logs are written to log server&lt;BR /&gt;Local Logging Mode Status: 0&lt;BR /&gt;Local Logging Sending Rate: 0&lt;BR /&gt;Log Handling Rate: 0&lt;/P&gt;&lt;P&gt;This is the output of the same command when the node becomes ACTIVE&lt;BR /&gt;Overall Status: 0&lt;BR /&gt;Overall Status Description: Security Gateway is reporting logs as defined&lt;BR /&gt;Local Logging Mode Description: Error - not writing logs&lt;BR /&gt;Local Logging Mode Status: 5&lt;BR /&gt;Local Logging Sending Rate: 0&lt;BR /&gt;Log Handling Rate: 0&lt;/P&gt;&lt;P&gt;the reason is: Log-Server Disconnected&lt;BR /&gt;&lt;BR /&gt;Anyone else has experienced the same issue?&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 11:52:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/81-20-Logging-issue-after-cluster-switch/m-p/242649#M47133</guid>
      <dc:creator>frenzetti</dc:creator>
      <dc:date>2025-02-28T11:52:35Z</dc:date>
    </item>
    <item>
      <title>Re: 81.20 Logging issue after cluster switch</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/81-20-Logging-issue-after-cluster-switch/m-p/242652#M47134</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/98167"&gt;@frenzetti&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you access the Active and Standby gateways on port tcp257 from the MGMT server on the node IPs?&lt;/P&gt;
&lt;P&gt;#telnet &amp;lt;ip&amp;gt; 257&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29750iA1F2A86DB7C2DD76/image-size/medium?v=v2&amp;amp;px=400" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;And reverse? From both gateways to the SMartCenter (or Log)&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 12:54:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/81-20-Logging-issue-after-cluster-switch/m-p/242652#M47134</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-02-28T12:54:21Z</dc:date>
    </item>
    <item>
      <title>Re: 81.20 Logging issue after cluster switch</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/81-20-Logging-issue-after-cluster-switch/m-p/242654#M47136</link>
      <description>&lt;P&gt;One easy fix (if it works) would be to try run fw logswitch on the gateways. Otherwise, just check what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/28415"&gt;@AkosBakos&lt;/a&gt;&amp;nbsp;suggested, and also, you can go through below sk.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk40090" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk40090&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 13:08:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/81-20-Logging-issue-after-cluster-switch/m-p/242654#M47136</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-28T13:08:18Z</dc:date>
    </item>
    <item>
      <title>Re: 81.20 Logging issue after cluster switch</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/81-20-Logging-issue-after-cluster-switch/m-p/242685#M47152</link>
      <description>&lt;P&gt;Thx AkosBakos for your reply.&lt;/P&gt;&lt;P&gt;We are able to reach both nodes from management and viceversa.&lt;/P&gt;&lt;P&gt;Logging is ok until we switch the cluster and node2 becomes active.&lt;/P&gt;&lt;P&gt;As soon the second node becomes active the issue arises&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 14:59:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/81-20-Logging-issue-after-cluster-switch/m-p/242685#M47152</guid>
      <dc:creator>frenzetti</dc:creator>
      <dc:date>2025-02-28T14:59:28Z</dc:date>
    </item>
    <item>
      <title>Re: 81.20 Logging issue after cluster switch</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/81-20-Logging-issue-after-cluster-switch/m-p/242686#M47153</link>
      <description>&lt;P&gt;Thx to you too, The Rock.&lt;/P&gt;&lt;P&gt;I will schedule a test (and other checks) next week. W.E. is a freeze-activities slot for customer&lt;/P&gt;&lt;P&gt;Thx again&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 15:01:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/81-20-Logging-issue-after-cluster-switch/m-p/242686#M47153</guid>
      <dc:creator>frenzetti</dc:creator>
      <dc:date>2025-02-28T15:01:06Z</dc:date>
    </item>
    <item>
      <title>Re: 81.20 Logging issue after cluster switch</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/81-20-Logging-issue-after-cluster-switch/m-p/242689#M47154</link>
      <description>&lt;P&gt;No worries. Btw, for what its worth, there is an old "trick" people would do in the old days to get logging working. It would not always be successful, but I find at least 80% of the time.&lt;/P&gt;
&lt;P&gt;Basically, what you do is create CP host, NOT regular host, but host that looks like mgmt object and you enable ONLY logging and then save it, give same IP as mgmt and then, you go to logging settings of your gw object, set logging to log to that new object and push policy.&lt;/P&gt;
&lt;P&gt;If that works, you give it a bit of time and then switch back to log to regular mgmt, if it works, awesome, then you can delete the new host object.&lt;/P&gt;
&lt;P&gt;I attached 3 screenshots for the reference.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 15:10:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/81-20-Logging-issue-after-cluster-switch/m-p/242689#M47154</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-28T15:10:51Z</dc:date>
    </item>
    <item>
      <title>Re: 81.20 Logging issue after cluster switch</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/81-20-Logging-issue-after-cluster-switch/m-p/243175#M47234</link>
      <description>&lt;P&gt;Just an update on topic&lt;BR /&gt;CP support discovered full log buffer error log and suggested applying SK52100.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2025 16:18:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/81-20-Logging-issue-after-cluster-switch/m-p/243175#M47234</guid>
      <dc:creator>frenzetti</dc:creator>
      <dc:date>2025-03-06T16:18:41Z</dc:date>
    </item>
  </channel>
</rss>

