<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Single VSY within VSX environment wont send logs to dedicated log server in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Single-VSY-within-VSX-environment-wont-send-logs-to-dedicated/m-p/257069#M43294</link>
    <description>&lt;P&gt;Try doing an 'Install database' on the log server (or just all the mgmt servers). This can commonly resolve logging issues with new gateways.&lt;/P&gt;</description>
    <pubDate>Wed, 10 Sep 2025 22:55:05 GMT</pubDate>
    <dc:creator>emmap</dc:creator>
    <dc:date>2025-09-10T22:55:05Z</dc:date>
    <item>
      <title>Single VSY within VSX environment wont send logs to dedicated log server</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Single-VSY-within-VSX-environment-wont-send-logs-to-dedicated/m-p/257037#M43281</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have a VSX environment running latest R81 hotfix. I have created a new virtual system ID 8 but I cant get it to communicate with the log server. The log server is in a separate network. There are a total of 8 virtual devices on this vsx, 5 systems/gateways, and 3 virtual switches. The other 4 virtual systems communicate with the log server fine.&lt;/P&gt;&lt;P&gt;When I do &lt;STRONG&gt;#cpstat fw -f log_connection&lt;/STRONG&gt; on the vsenv with the issue I get&lt;/P&gt;&lt;P&gt;&lt;EM&gt;:8]#&lt;STRONG&gt; cpstat fw -f log_connection&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Overall Status: 2&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Overall Status Description: Security Gateway is unable to report logs to any log server&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Local Logging Mode Description: Logs are written to log server&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Local Logging Mode Status: 0&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Local Logging Sending Rate: 0&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Log Handling Rate: 0&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;EM&gt;Log Servers Connections&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;-----------------------------------------------------------&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;|IP |Status|Status Description |Sending Rate|&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;-----------------------------------------------------------&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;|&lt;STRONG&gt;172.25.116.31| 1|Log-Server Disconnected| 0|&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;-----------------------------------------------------------&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;And if I go to vsenv 0 and do &lt;STRONG&gt;#netstat -nap | grep 172.25.116.31&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;:0]# &lt;STRONG&gt;netstat -nap | grep 172.25.116.31&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;tcp 0 0 172.20.253.60:46836 172.25.116.31:257 &lt;STRONG&gt;TIME_WAIT&lt;/STRONG&gt; -&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;tcp 0 0 172.20.253.60:34374 172.25.116.31:257 ESTABLISHED 5432/fwd&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;tcp 0 0 172.20.253.60:56275 172.25.116.31:257 ESTABLISHED 6098/fwd&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;tcp 0 0 172.20.253.60:50498 172.25.116.31:257 ESTABLISHED 6186/fwd&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;tcp 0 0 172.20.253.60:64858 172.25.116.31:257 ESTABLISHED 5922/fwd&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;The above must show the five virtual systems communicating (or trying to) with the log server with 4 Established and working and one Time_Wait and not working. But it shows end to end connectivity between the mgmt interface and the server.&lt;/P&gt;&lt;P&gt;I can configure the new virtual system to send logs to our SMS server 172.20.116.30 and that works&lt;/P&gt;&lt;P&gt;&lt;EM&gt;:8]# &lt;STRONG&gt;cpstat fw -f log_connection&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Overall Status: 0&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Overall Status Description: Security Gateway is reporting logs as defined&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Local Logging Mode Description: Writing logs locally due to connectivity problems&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Local Logging Mode Status: 2&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Local Logging Sending Rate: 0&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Log Handling Rate: 0&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;EM&gt;Log Servers Connections&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;--------------------------------------------------------&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;|IP |Status|Status Description |Sending Rate|&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;--------------------------------------------------------&lt;/EM&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;|172.20.116.30| 0|Log-Server Connected| 0|&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;EM&gt;--------------------------------------------------------&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;And if I send some dummy ping from that vsenv 8 to the Internet it shows in the logs. See attachments.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;8]# &lt;STRONG&gt;ping 14.15.16.17&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;PING 14.15.16.17 (14.15.16.17) 56(84) bytes of data.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;^C&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;--- 14.15.16.17 ping statistics ---&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;150 packets transmitted, 0 received, 100% packet loss, time 149000ms&lt;/EM&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;So I dont know where to look now. It may be something on the dedicated log server but I am unfamiliar with troubleshooting on that.&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Sep 2025 14:13:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Single-VSY-within-VSX-environment-wont-send-logs-to-dedicated/m-p/257037#M43281</guid>
      <dc:creator>P_Williams</dc:creator>
      <dc:date>2025-09-10T14:13:11Z</dc:date>
    </item>
    <item>
      <title>Re: Single VSY within VSX environment wont send logs to dedicated log server</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Single-VSY-within-VSX-environment-wont-send-logs-to-dedicated/m-p/257069#M43294</link>
      <description>&lt;P&gt;Try doing an 'Install database' on the log server (or just all the mgmt servers). This can commonly resolve logging issues with new gateways.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Sep 2025 22:55:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Single-VSY-within-VSX-environment-wont-send-logs-to-dedicated/m-p/257069#M43294</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2025-09-10T22:55:05Z</dc:date>
    </item>
    <item>
      <title>Re: Single VSY within VSX environment wont send logs to dedicated log server</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Single-VSY-within-VSX-environment-wont-send-logs-to-dedicated/m-p/257086#M43300</link>
      <description>&lt;P&gt;Thank you emmap, that has fixed it&lt;/P&gt;&lt;P&gt;&lt;EM&gt;0]# netstat -nap | grep 172.25.116.31&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;tcp 0 0 172.20.253.60:56329 172.25.116.31:257 ESTABLISHED 6027/fwd&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;tcp 0 0 172.20.253.60:34374 172.25.116.31:257 ESTABLISHED 5432/fwd&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;tcp 0 0 172.20.253.60:56275 172.25.116.31:257 ESTABLISHED 6098/fwd&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;tcp 0 0 172.20.253.60:50498 172.25.116.31:257 ESTABLISHED 6186/fwd&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;tcp 0 0 172.20.253.60:64858 172.25.116.31:257 ESTABLISHED 5922/fwd&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Sep 2025 07:41:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Single-VSY-within-VSX-environment-wont-send-logs-to-dedicated/m-p/257086#M43300</guid>
      <dc:creator>P_Williams</dc:creator>
      <dc:date>2025-09-11T07:41:51Z</dc:date>
    </item>
  </channel>
</rss>

