<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Check which gateways are logging in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-which-gateways-are-logging/m-p/105538#M77338</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have noticed some of my gateways don't appear to be logging traffic, This am am certain was working for all gateways previously. We have 45 gateway son the management server so I would ideally like a command I can run on the log sever to see which are established so I can work through backwards.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have 24 cloudguard gateways in hypervisor mode and it seems to be some of them that aren't working, So I cannot easily tell which ones aren't not logging, but I just know when I should be seeing traffic and I am not. The log server has plenty of disk space.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
    <pubDate>Wed, 16 Dec 2020 04:31:50 GMT</pubDate>
    <dc:creator>Ryan_Ryan</dc:creator>
    <dc:date>2020-12-16T04:31:50Z</dc:date>
    <item>
      <title>Check which gateways are logging</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-which-gateways-are-logging/m-p/105538#M77338</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have noticed some of my gateways don't appear to be logging traffic, This am am certain was working for all gateways previously. We have 45 gateway son the management server so I would ideally like a command I can run on the log sever to see which are established so I can work through backwards.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have 24 cloudguard gateways in hypervisor mode and it seems to be some of them that aren't working, So I cannot easily tell which ones aren't not logging, but I just know when I should be seeing traffic and I am not. The log server has plenty of disk space.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Wed, 16 Dec 2020 04:31:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-which-gateways-are-logging/m-p/105538#M77338</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2020-12-16T04:31:50Z</dc:date>
    </item>
    <item>
      <title>Re: Check which gateways are logging</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-which-gateways-are-logging/m-p/105540#M77339</link>
      <description>&lt;P&gt;netstat -an should show active TCP connections with gateways that are logging.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Dec 2020 04:48:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-which-gateways-are-logging/m-p/105540#M77339</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-16T04:48:09Z</dc:date>
    </item>
    <item>
      <title>Re: Check which gateways are logging</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-which-gateways-are-logging/m-p/105542#M77340</link>
      <description>&lt;P&gt;I did some further testing and found a specific gateway that is not logging, I have an snmp alarm on that device:&amp;nbsp; A "chkpntTrapOverallLSConnState" event has occurred, from CheckpointFirewall device,&amp;nbsp;Security Gateway is unable to report logs to any log server fwLocalLoggingDesc = Writing logs locally due to connectivity problems fwLocalLoggingStat = 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can ping the log server from this gateway, and the fw.log file is not increasing either, just did an install database on the all the management servers, and a cpstart on the gateway really weird. Ive run through&amp;nbsp;&lt;SPAN&gt;sk40090 without any luck either. Looks like I have 3 gateways that all stopped logging at the exact same time. netstat -an doesn't&amp;nbsp;show a connection&amp;nbsp;to log server&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Dec 2020 04:54:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-which-gateways-are-logging/m-p/105542#M77340</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2020-12-16T04:54:55Z</dc:date>
    </item>
    <item>
      <title>Re: Check which gateways are logging</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-which-gateways-are-logging/m-p/105549#M77341</link>
      <description>&lt;P&gt;Don’t know that you need to delete logtrack but restarting fwd can’t hurt.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk170331&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk170331&amp;amp;partition=Advanced&amp;amp;product=Security&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Dec 2020 07:04:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-which-gateways-are-logging/m-p/105549#M77341</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-16T07:04:49Z</dc:date>
    </item>
    <item>
      <title>Re: Check which gateways are logging</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-which-gateways-are-logging/m-p/105702#M77342</link>
      <description>&lt;P&gt;Yes I think you are right, does restarting FWD have any service impact?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I saw this in the logs which looks very similar to&amp;nbsp;sk118936&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-[17 Dec 15:55:49] connect_to_local_server: connected to local server successfuly&lt;BR /&gt;-[17 Dec 15:55:49] ....&amp;lt;-- connect_to_local_server&lt;BR /&gt;-[17 Dec 15:55:49] ...&amp;lt;-- connect_to_server&lt;BR /&gt;-[17 Dec 15:55:49] create_default_log: connected to default log server&lt;BR /&gt;-[17 Dec 15:55:49] ...--&amp;gt; disconnect_from_server&lt;BR /&gt;-[17 Dec 15:55:49] disconnect_from_server: default still backups other servers, don't disconnect&lt;BR /&gt;-[17 Dec 15:55:49] ...&amp;lt;-- disconnect_from_server&lt;BR /&gt;-[17 Dec 15:55:49] create_default_log: disconnected from default log server&lt;BR /&gt;-[17 Dec 15:55:49] ..&amp;lt;-- create_default_log&lt;BR /&gt;-[17 Dec 15:55:49] .&amp;lt;-- logbuf_write&lt;BR /&gt;-[17 Dec 15:55:49] .--&amp;gt; log_has_connected_server&lt;BR /&gt;-[17 Dec 15:55:49] .&amp;lt;-- log_has_connected_server&lt;BR /&gt;-[17 Dec 15:55:49] log_add_e__logclient: writes logs to local disk because overflow&lt;BR /&gt;-[17 Dec 15:55:49] log_add_e__logclient: 192.168.10.10 - no log is sent now&lt;BR /&gt;-[17 Dec 15:55:49] log_add_e__logclient: waiting for connecting callback (log_connected) to be read&lt;BR /&gt;-[17 Dec 15:55:49] log_add_e__logclient: Write locally ! log record number = 5342&lt;BR /&gt;-[17 Dec 15:55:49] .--&amp;gt; log_local_write&lt;BR /&gt;-[17 Dec 15:55:49] .&amp;lt;-- log_local_write&lt;BR /&gt;-[17 Dec 15:55:49] &amp;lt;-- log_add_e__logclient&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2020 03:27:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-which-gateways-are-logging/m-p/105702#M77342</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2020-12-17T03:27:57Z</dc:date>
    </item>
    <item>
      <title>Re: Check which gateways are logging</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-which-gateways-are-logging/m-p/105704#M77343</link>
      <description>&lt;P&gt;I don’t believe so but the sk suggests doing during a maintenance window.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2020 04:11:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-which-gateways-are-logging/m-p/105704#M77343</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-17T04:11:24Z</dc:date>
    </item>
    <item>
      <title>Re: Check which gateways are logging</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-which-gateways-are-logging/m-p/105812#M77344</link>
      <description>&lt;P&gt;found another solution, removing the log server from the gateway, push policy and add it back has got he log connection back up and working now.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2020 02:35:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-which-gateways-are-logging/m-p/105812#M77344</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2020-12-18T02:35:36Z</dc:date>
    </item>
  </channel>
</rss>

