<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Syslog traffic in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Syslog-traffic/m-p/253141#M49607</link>
    <description>&lt;P&gt;Where should we find this setting “perform_cluster_hide_fold” ? &amp;nbsp;is this setting for global level or for individual cluster VIP interface level ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are seeing the syslog traffic being sourced from VIP and one of the physical IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the syslog traffic sourced from Virtual IP, how do we verify that the syslog data is being sent by both Active and Standby Firewall ?&lt;/P&gt;</description>
    <pubDate>Tue, 15 Jul 2025 04:56:41 GMT</pubDate>
    <dc:creator>tavi0906</dc:creator>
    <dc:date>2025-07-15T04:56:41Z</dc:date>
    <item>
      <title>Syslog traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Syslog-traffic/m-p/253141#M49607</link>
      <description>&lt;P&gt;Where should we find this setting “perform_cluster_hide_fold” ? &amp;nbsp;is this setting for global level or for individual cluster VIP interface level ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are seeing the syslog traffic being sourced from VIP and one of the physical IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the syslog traffic sourced from Virtual IP, how do we verify that the syslog data is being sent by both Active and Standby Firewall ?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jul 2025 04:56:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Syslog-traffic/m-p/253141#M49607</guid>
      <dc:creator>tavi0906</dc:creator>
      <dc:date>2025-07-15T04:56:41Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Syslog-traffic/m-p/253142#M49608</link>
      <description>&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk34180" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk34180: Outgoing connections from cluster members are sent with cluster Virtual IP address instead of member's Physical IP address&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk154272" target="_blank" rel="noopener"&gt;sk154272: Changing the value of "&lt;STRONG&gt;perform_cluster_hide_fold&lt;/STRONG&gt;" field does not change the ClusterXL behavior&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jul 2025 05:53:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Syslog-traffic/m-p/253142#M49608</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-07-15T05:53:28Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Syslog-traffic/m-p/253145#M49609</link>
      <description>&lt;P&gt;“perform_cluster_hide_fold” ? &amp;nbsp;is this setting for global level or for individual cluster VIP interface level ?&lt;/P&gt;&lt;P&gt;we are seeing the syslog traffic being sourced from VIP and one of the physical IP.&lt;/P&gt;&lt;P&gt;If the syslog traffic sourced from Virtual IP, how do we verify that the syslog data is being sent by both Active and Standby Firewall ?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jul 2025 06:02:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Syslog-traffic/m-p/253145#M49609</guid>
      <dc:creator>tavi0906</dc:creator>
      <dc:date>2025-07-15T06:02:14Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Syslog-traffic/m-p/253147#M49610</link>
      <description>&lt;P&gt;Please read&amp;nbsp;&lt;SPAN class="css-13y3t3g"&gt;&lt;SPAN class="css-vy7rm"&gt;sk34180&lt;/SPAN&gt;&lt;/SPAN&gt;&amp;nbsp;to learn that this is configured on cluster level,&amp;nbsp;in Cluster Object in Security Management Server database.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jul 2025 06:08:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Syslog-traffic/m-p/253147#M49610</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-07-15T06:08:30Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Syslog-traffic/m-p/253171#M49612</link>
      <description>&lt;P&gt;&lt;SPAN&gt;If the syslog traffic sourced from Virtual IP, how do we verify that the syslog data is being sent by both Active and Standby Firewall ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jul 2025 10:33:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Syslog-traffic/m-p/253171#M49612</guid>
      <dc:creator>tavi0906</dc:creator>
      <dc:date>2025-07-15T10:33:42Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Syslog-traffic/m-p/253173#M49613</link>
      <description>&lt;P&gt;What do you you want to know from StandBy member syslog ? Usually that member does nothing but sync some tables...&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jul 2025 10:36:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Syslog-traffic/m-p/253173#M49613</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-07-15T10:36:11Z</dc:date>
    </item>
    <item>
      <title>Re: syslog traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Syslog-traffic/m-p/253234#M49636</link>
      <description>&lt;P&gt;fw monitor from the standby member should show the standby member sending syslog (if it is doing so).&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jul 2025 18:39:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Syslog-traffic/m-p/253234#M49636</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-07-15T18:39:06Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Syslog-traffic/m-p/253240#M49637</link>
      <description>&lt;P&gt;Do couple incorrect passwords on stand-by member this will trigger syslog event if you do it wrong often enough.&lt;/P&gt;
&lt;P&gt;Also I suspect hostname is included in the syslog data, so you will see syslog from 1 IP only but in the data itself you can see if it is member 1 or 2.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jul 2025 19:26:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Syslog-traffic/m-p/253240#M49637</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-07-15T19:26:27Z</dc:date>
    </item>
  </channel>
</rss>

