<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Virtual System (in VSX) Logging in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-System-in-VSX-Logging/m-p/188838#M67721</link>
    <description>&lt;P&gt;when I check in particular VS , &lt;SPAN&gt;&amp;nbsp;"cpstat fw -f log_connection" showing primary log servers as disconnected&amp;nbsp;but in VS0 same command output is 'connected.'&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 08 Aug 2023 03:37:32 GMT</pubDate>
    <dc:creator>JSingh_N</dc:creator>
    <dc:date>2023-08-08T03:37:32Z</dc:date>
    <item>
      <title>Virtual System (in VSX) Logging</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-System-in-VSX-Logging/m-p/188779#M67716</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have doubt in virtual system logging mechanism.&lt;/P&gt;&lt;P&gt;We have configured 2 dedicated log servers as primary log servers and 1 as backup log server in VS.&lt;/P&gt;&lt;P&gt;1.) When I run command "cpstat fw -f log_connection" I see primary log servers as connected but secondary / backup log server as disconnected.&lt;/P&gt;&lt;P&gt;2,) When I run command "tcpdump -nni any tcp port 257" in particular VS context, I am not able to see any traffic, also netstat -an | grep 257 does not show any connection.&lt;/P&gt;&lt;P&gt;3.) However, when I run&amp;nbsp;"tcpdump -nni any tcp port 257" in VS0, then I am able to see the traffic for log servers and also able to see the connection established for 'netstat -an | grep 257'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In few of the VS, I see output&amp;nbsp;&amp;nbsp;of "cpstat fw -f log_connection" as disconnected for all three log servers but able to see logs in SmartConsole logs.&lt;/P&gt;&lt;P&gt;Please share your inputs regarding this behavior of VS logging.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jaspal Singh&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2023 11:52:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-System-in-VSX-Logging/m-p/188779#M67716</guid>
      <dc:creator>JSingh_N</dc:creator>
      <dc:date>2023-08-07T11:52:24Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual System (in VSX) Logging</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-System-in-VSX-Logging/m-p/188792#M67717</link>
      <description>&lt;P&gt;Primary Log servers all receive the logs, but secondary is used when one or all primary log servers are unreachable.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2023 12:59:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-System-in-VSX-Logging/m-p/188792#M67717</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-08-07T12:59:37Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual System (in VSX) Logging</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-System-in-VSX-Logging/m-p/188802#M67718</link>
      <description>&lt;P&gt;Ok, thanks for the revert. I got your point.&lt;/P&gt;&lt;P&gt;Could you please share your inputs for point 2 and 3 as well?&lt;/P&gt;&lt;P&gt;I think there is some mechanism in case of VSX env. that I am not aware of. May be some sort of mapping with VS0 or similar to this, I am not sure for now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2023 14:04:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-System-in-VSX-Logging/m-p/188802#M67718</guid>
      <dc:creator>JSingh_N</dc:creator>
      <dc:date>2023-08-07T14:04:56Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual System (in VSX) Logging</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-System-in-VSX-Logging/m-p/188803#M67719</link>
      <description>&lt;P&gt;Logging for all VSs is done from VS0 context, this should cover 2 &amp;amp; 3&lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2023 14:06:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-System-in-VSX-Logging/m-p/188803#M67719</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-08-07T14:06:40Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual System (in VSX) Logging</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-System-in-VSX-Logging/m-p/188815#M67720</link>
      <description>&lt;P&gt;Expanding on this, almost all outgoing traffic is sent from VS0. Traffic logs. Syslog data. DNS requests. NTP. RADIUS or TACACS for authentication.&lt;/P&gt;
&lt;P&gt;VPN negotiations are the only thing I can think of offhand which originates from the firewall, but which leaves using the routing table of a VS other than 0.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2023 16:54:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-System-in-VSX-Logging/m-p/188815#M67720</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-08-07T16:54:59Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual System (in VSX) Logging</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-System-in-VSX-Logging/m-p/188838#M67721</link>
      <description>&lt;P&gt;when I check in particular VS , &lt;SPAN&gt;&amp;nbsp;"cpstat fw -f log_connection" showing primary log servers as disconnected&amp;nbsp;but in VS0 same command output is 'connected.'&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 03:37:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-System-in-VSX-Logging/m-p/188838#M67721</guid>
      <dc:creator>JSingh_N</dc:creator>
      <dc:date>2023-08-08T03:37:32Z</dc:date>
    </item>
  </channel>
</rss>

