<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Checkpoint firewall logging source interface in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-firewall-logging-source-interface/m-p/63552#M12901</link>
    <description>&lt;P&gt;Hi Ilya,&lt;/P&gt;&lt;P&gt;I have configured static NAT so the public IP will be replaced with one of the internal IPs configured on the cluster but still, the packets leave the firewall with the original source IP which is the public.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The external interface IP is 192.192.192.254 and the internal interface IP is 10.1.1.254&lt;/P&gt;&lt;P&gt;I have configured a NAT rule that says" original source - 192.192.192.254" to target 192.168.1.1, replace with the source of 10.1.1.254 and the target remains original.&lt;/P&gt;&lt;P&gt;I tried static and hide NAT and the same result - the source is unchanged.&lt;/P&gt;&lt;P&gt;Any thoughts?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 24 Sep 2019 11:57:11 GMT</pubDate>
    <dc:creator>motiami</dc:creator>
    <dc:date>2019-09-24T11:57:11Z</dc:date>
    <item>
      <title>Checkpoint firewall logging source interface</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-firewall-logging-source-interface/m-p/7846#M976</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On a Cisco router I could specify syslog is sent from one of its interfaces such as loopback.&amp;nbsp; On a checkpoint firewall could I source syslog from an interface other than what is configured as management that is established with SIC?&amp;nbsp; If not, how could I source syslog from a different interface?&amp;nbsp; thank you&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Oct 2017 05:36:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-firewall-logging-source-interface/m-p/7846#M976</guid>
      <dc:creator>Wayne_Situ</dc:creator>
      <dc:date>2017-10-25T05:36:38Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint firewall logging source interface</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-firewall-logging-source-interface/m-p/7847#M977</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The IP used is determined by the routing table in the OS, using the egress interface IP as the source IP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suppose you could create a NAT rule to source&amp;nbsp;the relevant traffic from the desired IP.&lt;/P&gt;&lt;P&gt;What's the problem you're trying to solve here?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Oct 2017 12:36:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-firewall-logging-source-interface/m-p/7847#M977</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-10-25T12:36:46Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint firewall logging source interface</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-firewall-logging-source-interface/m-p/57143#M11492</link>
      <description>&lt;P&gt;Nat Don't work. Any Idea ?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2019 15:19:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-firewall-logging-source-interface/m-p/57143#M11492</guid>
      <dc:creator>GabsOliv</dc:creator>
      <dc:date>2019-07-01T15:19:50Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint firewall logging source interface</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-firewall-logging-source-interface/m-p/57153#M11495</link>
      <description>&lt;P&gt;Add a host route for your syslog server out the interface you want to source the traffic from off the gateway.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2019 17:17:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-firewall-logging-source-interface/m-p/57153#M11495</guid>
      <dc:creator>Mike_A</dc:creator>
      <dc:date>2019-07-01T17:17:29Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint firewall logging source interface</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-firewall-logging-source-interface/m-p/59349#M11985</link>
      <description>&lt;P&gt;I have the same issue where the module is sending logs to the management server using it's external IP as a source for the packets but the SIC between the mgmt server and the FW module is build based on the management IP which is a private IP.&lt;/P&gt;&lt;P&gt;The return traffic does not routed over our WAN network but over the internet and this is incorrect.&lt;/P&gt;&lt;P&gt;is there a way to set the source interface of the logs to be the Mgmt0 interface?&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2019 12:25:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-firewall-logging-source-interface/m-p/59349#M11985</guid>
      <dc:creator>motiami</dc:creator>
      <dc:date>2019-07-31T12:25:57Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint firewall logging source interface</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-firewall-logging-source-interface/m-p/59758#M12084</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;In my case, solved the issue, creating a dummy object&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2019 23:30:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-firewall-logging-source-interface/m-p/59758#M12084</guid>
      <dc:creator>GabsOliv</dc:creator>
      <dc:date>2019-08-06T23:30:03Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint firewall logging source interface</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-firewall-logging-source-interface/m-p/59768#M12089</link>
      <description>&lt;P&gt;Hello and thanks for your reply.&lt;/P&gt;&lt;P&gt;I don't understand your solution, can you please elaborate?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2019 03:03:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-firewall-logging-source-interface/m-p/59768#M12089</guid>
      <dc:creator>motiami</dc:creator>
      <dc:date>2019-08-07T03:03:04Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint firewall logging source interface</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-firewall-logging-source-interface/m-p/59772#M12090</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You have 2 options:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Configure Syslog Server behind the interface you want to be the source of syslog messages.&lt;/P&gt;
&lt;P&gt;2. You can configure Syslog server behind any interface and you can do Static NAT on a range of the desired interface, it should work.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2019 05:54:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-firewall-logging-source-interface/m-p/59772#M12090</guid>
      <dc:creator>Ilya_Yusupov</dc:creator>
      <dc:date>2019-08-07T05:54:50Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint firewall logging source interface</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-firewall-logging-source-interface/m-p/59794#M12096</link>
      <description>On the gateways did you try setting the MGMT interface: "set management interface &amp;lt;if_name&amp;gt;"</description>
      <pubDate>Wed, 07 Aug 2019 08:36:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-firewall-logging-source-interface/m-p/59794#M12096</guid>
      <dc:creator>Moe_89</dc:creator>
      <dc:date>2019-08-07T08:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint firewall logging source interface</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-firewall-logging-source-interface/m-p/63552#M12901</link>
      <description>&lt;P&gt;Hi Ilya,&lt;/P&gt;&lt;P&gt;I have configured static NAT so the public IP will be replaced with one of the internal IPs configured on the cluster but still, the packets leave the firewall with the original source IP which is the public.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The external interface IP is 192.192.192.254 and the internal interface IP is 10.1.1.254&lt;/P&gt;&lt;P&gt;I have configured a NAT rule that says" original source - 192.192.192.254" to target 192.168.1.1, replace with the source of 10.1.1.254 and the target remains original.&lt;/P&gt;&lt;P&gt;I tried static and hide NAT and the same result - the source is unchanged.&lt;/P&gt;&lt;P&gt;Any thoughts?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2019 11:57:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-firewall-logging-source-interface/m-p/63552#M12901</guid>
      <dc:creator>motiami</dc:creator>
      <dc:date>2019-09-24T11:57:11Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint firewall logging source interface</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-firewall-logging-source-interface/m-p/78574#M15996</link>
      <description>Is there any solution for this issue ?</description>
      <pubDate>Tue, 17 Mar 2020 16:42:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-firewall-logging-source-interface/m-p/78574#M15996</guid>
      <dc:creator>emreturkmenler</dc:creator>
      <dc:date>2020-03-17T16:42:09Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint firewall logging source interface</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-firewall-logging-source-interface/m-p/78586#M16001</link>
      <description>&lt;P&gt;as far as i remember there was no issue but miss configuration.&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/28972"&gt;@motiami&lt;/a&gt;&amp;nbsp; - can you share what was missing as i don't remember 100%.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Mar 2020 19:11:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-firewall-logging-source-interface/m-p/78586#M16001</guid>
      <dc:creator>Ilya_Yusupov</dc:creator>
      <dc:date>2020-03-17T19:11:57Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint firewall logging source interface</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-firewall-logging-source-interface/m-p/88947#M17869</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;It'll certainly makes out lives bit better in case Check Point introduce a command to set the source interface for syslog&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jun 2020 20:57:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-firewall-logging-source-interface/m-p/88947#M17869</guid>
      <dc:creator>_Daniel_</dc:creator>
      <dc:date>2020-06-17T20:57:24Z</dc:date>
    </item>
  </channel>
</rss>

