<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MGT server not receiving logs in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MGT-server-not-receiving-logs/m-p/156538#M71079</link>
    <description>&lt;P&gt;1.- Check if you have a NAT what can affect SMS and GW&lt;/P&gt;
&lt;P&gt;2.-Create a dummy log server and change in the gateway to send log to that one, push policy and rever the changes.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3.-Check the disk space on management&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk60080&amp;amp;partition=General&amp;amp;product=Security" target="_self"&gt;&lt;SPAN&gt;sk60080&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;4.-check on SMS if you are listeninglogs with tcpdump -anp | grep :257&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk40090&amp;amp;partition=General&amp;amp;product=Security" target="_self"&gt;sk40090&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 05 Sep 2022 16:58:37 GMT</pubDate>
    <dc:creator>Dario_Perez</dc:creator>
    <dc:date>2022-09-05T16:58:37Z</dc:date>
    <item>
      <title>MGT server not receiving logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MGT-server-not-receiving-logs/m-p/156520#M71078</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have had an issue where our CP fw's do not send logs to the mgt server . We have had a ticket open with CP since Jan. We have had remote sessions etc, sent logs off of to them but no joy. It stopped working since we reloaded them and applied a hotfix.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We had a workaround where we could delete the mgt server from the cluster, push a policy, add it back in again, push a policy and it would work until we pushed a another policy and we had to repeat the process again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This has now stopped working for some reason! We are running 80.30 on GAIA (5200) with the mgt server on a diff internal ip address to the two firewalls.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have been off work for two weeks and this could be one of the most stupid questions you have ever received but in the rule base we have the mgt server allowed to talk to the firewalls but not the other way round. I'm sure nobody has changed this since i have been off but would this now be a factor or was it from the beginning ? Excuse my ignorance but CP are not my speciality.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jon.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Sep 2022 14:11:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MGT-server-not-receiving-logs/m-p/156520#M71078</guid>
      <dc:creator>JonWilliams</dc:creator>
      <dc:date>2022-09-05T14:11:17Z</dc:date>
    </item>
    <item>
      <title>Re: MGT server not receiving logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MGT-server-not-receiving-logs/m-p/156538#M71079</link>
      <description>&lt;P&gt;1.- Check if you have a NAT what can affect SMS and GW&lt;/P&gt;
&lt;P&gt;2.-Create a dummy log server and change in the gateway to send log to that one, push policy and rever the changes.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3.-Check the disk space on management&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk60080&amp;amp;partition=General&amp;amp;product=Security" target="_self"&gt;&lt;SPAN&gt;sk60080&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;4.-check on SMS if you are listeninglogs with tcpdump -anp | grep :257&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk40090&amp;amp;partition=General&amp;amp;product=Security" target="_self"&gt;sk40090&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Sep 2022 16:58:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MGT-server-not-receiving-logs/m-p/156538#M71079</guid>
      <dc:creator>Dario_Perez</dc:creator>
      <dc:date>2022-09-05T16:58:37Z</dc:date>
    </item>
    <item>
      <title>Re: MGT server not receiving logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MGT-server-not-receiving-logs/m-p/156581#M71080</link>
      <description>&lt;P&gt;Adding to what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3205"&gt;@Dario_Perez&lt;/a&gt;&amp;nbsp;wrote, you stated that "&lt;SPAN&gt;push a policy and it would work until we pushed a another policy and we had to repeat the process again."&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;This definitely sounds like something in the policy might cause this. Is there another Security Gateway in-between the Security Management and other Gateways?&lt;BR /&gt;I would also check the Anti-Spoofing definitions (try to disable) and Implied Rule settings.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also can you share the ticket (SR) you opened with TAC?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2022 06:49:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MGT-server-not-receiving-logs/m-p/156581#M71080</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2022-09-06T06:49:38Z</dc:date>
    </item>
    <item>
      <title>Re: MGT server not receiving logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MGT-server-not-receiving-logs/m-p/156639#M71081</link>
      <description>&lt;P&gt;Hi thanks Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ticket with TAC is&amp;nbsp;&lt;SPAN&gt;6-0003125417&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was on the phone with CP for two hours today.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When they edited the file the "masters" file and replaced the "log" name with the ip address of the mgt server, logging started straight away.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As soon as i pushed a policy it stopped working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The command cpstat&amp;nbsp; fw -f log_connection showed the floating public ip address as the log server after the policy was pushed&amp;nbsp; which is the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When they edited the masters file with the local mgt ip address it was working which was correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;They suggested setting up a no nat rule from&amp;nbsp; the fw's to the mgt server ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;They then said to hold fire on this whilst they investigate further. Thoughts ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2022 14:18:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MGT-server-not-receiving-logs/m-p/156639#M71081</guid>
      <dc:creator>JonWilliams</dc:creator>
      <dc:date>2022-09-06T14:18:53Z</dc:date>
    </item>
    <item>
      <title>Re: MGT server not receiving logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MGT-server-not-receiving-logs/m-p/156721#M71082</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ticket number is&amp;nbsp;&lt;SPAN&gt;6-0003125417&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When the masters file was edited to use the ip address instead of them name it worked. When we push a policy it stops working again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Where does the masters file get the ip address for the mgt server ? Is it via the DNS server used on the fw ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2022 07:51:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MGT-server-not-receiving-logs/m-p/156721#M71082</guid>
      <dc:creator>JonWilliams</dc:creator>
      <dc:date>2022-09-07T07:51:14Z</dc:date>
    </item>
    <item>
      <title>Re: MGT server not receiving logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MGT-server-not-receiving-logs/m-p/156733#M71083</link>
      <description>&lt;P&gt;It should take it from the actual database.&lt;/P&gt;
&lt;P&gt;What about the previous questions - like Management behind NAT, Gateway between Management and other Gateways, Anti-Spoofing etc.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2022 10:32:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MGT-server-not-receiving-logs/m-p/156733#M71083</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2022-09-07T10:32:20Z</dc:date>
    </item>
    <item>
      <title>Re: MGT server not receiving logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MGT-server-not-receiving-logs/m-p/156757#M71084</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;When we push&amp;nbsp;a policy the master file record for log changes from the ip address to the logging server name. Should that happen ?&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Rgds,&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2022 15:11:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MGT-server-not-receiving-logs/m-p/156757#M71084</guid>
      <dc:creator>JonWilliams</dc:creator>
      <dc:date>2022-09-07T15:11:11Z</dc:date>
    </item>
    <item>
      <title>Re: MGT server not receiving logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MGT-server-not-receiving-logs/m-p/156763#M71085</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Yes, that is the expected behavior. The keep your changes after policy installation follow&amp;nbsp;&lt;SPAN&gt;sk102712. It is specific per gateway/cluster, if you have many gateways managed by this server, you have to do this in every gateway.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You can also check if the gateway is trying to send logs to a wrong IP address with&amp;nbsp;&lt;STRONG&gt;&lt;EM&gt;cpstat -f log_connection fw.&amp;nbsp;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2022 16:19:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MGT-server-not-receiving-logs/m-p/156763#M71085</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2022-09-07T16:19:44Z</dc:date>
    </item>
    <item>
      <title>Re: MGT server not receiving logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MGT-server-not-receiving-logs/m-p/156768#M71086</link>
      <description>&lt;P&gt;The default in masters file should be the name. Here is workaround I did many times:&lt;/P&gt;
&lt;P&gt;-create CP host where you can enable logging (NOT regular host where you just place IP and name)&lt;/P&gt;
&lt;P&gt;-give it same IP as mgmt server&lt;/P&gt;
&lt;P&gt;save, install database on ACTUAL mgmt server&lt;/P&gt;
&lt;P&gt;-open gateway object, go to logging and select new object you created for logging&lt;/P&gt;
&lt;P&gt;-push policy -&amp;gt; test -&amp;gt; if it works, give it few mins, revert changes and test&lt;/P&gt;
&lt;P&gt;-if it works, great, if not, then I would follow below:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk38848" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk38848&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk40090" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk40090&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2022 16:54:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MGT-server-not-receiving-logs/m-p/156768#M71086</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-09-07T16:54:31Z</dc:date>
    </item>
    <item>
      <title>Re: MGT server not receiving logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MGT-server-not-receiving-logs/m-p/156796#M71087</link>
      <description>&lt;P&gt;Hi Alan,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the mail. Where do i create this and do i have to delete the original entry for the logging server ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry, my cp skills are not great.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jon.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2022 07:46:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MGT-server-not-receiving-logs/m-p/156796#M71087</guid>
      <dc:creator>JonWilliams</dc:creator>
      <dc:date>2022-09-08T07:46:44Z</dc:date>
    </item>
    <item>
      <title>Re: MGT server not receiving logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MGT-server-not-receiving-logs/m-p/156847#M71088</link>
      <description>&lt;P&gt;Message me privately and we can do remote, if privacy is a concern, I can show it to you in my lab.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2022 15:48:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MGT-server-not-receiving-logs/m-p/156847#M71088</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-09-08T15:48:43Z</dc:date>
    </item>
    <item>
      <title>Re: MGT server not receiving logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MGT-server-not-receiving-logs/m-p/156901#M71089</link>
      <description>&lt;P&gt;Hi Andy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks, are you available on Monday from say midday bst ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 09:11:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MGT-server-not-receiving-logs/m-p/156901#M71089</guid>
      <dc:creator>JonWilliams</dc:creator>
      <dc:date>2022-09-09T09:11:20Z</dc:date>
    </item>
    <item>
      <title>Re: MGT server not receiving logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MGT-server-not-receiving-logs/m-p/156903#M71090</link>
      <description>&lt;P&gt;I should be, yes.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 10:27:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MGT-server-not-receiving-logs/m-p/156903#M71090</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-09-09T10:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: MGT server not receiving logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MGT-server-not-receiving-logs/m-p/193677#M71091</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What resolved your issue?&lt;/P&gt;&lt;P&gt;WR,&lt;/P&gt;&lt;P&gt;Shira&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 13:13:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MGT-server-not-receiving-logs/m-p/193677#M71091</guid>
      <dc:creator>Shira</dc:creator>
      <dc:date>2023-09-27T13:13:12Z</dc:date>
    </item>
  </channel>
</rss>

