<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R80.20 syslog - TLS in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/R80-20-syslog-TLS/m-p/32953#M6885</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are having similar issues with R80.10 log exporter to rsyslog, same ssl connect failed error - I have asked TAC how we can get more detailed output on the SSL connect as really this error message&amp;nbsp;does not provide enough detail.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Having tested with openssl s_client -connect, if i use a fully chained root CA pem file the handshake to the rsyslog server works fine. If i use this same CA cert file in the Log Exporter config then it fails to parse the CA cert file - doesnt seem to like a pem file with chained certs. If i use the intermediate cert as the CA file then LogExport does not complain but ssl connect fails.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In regards the LEA&amp;nbsp; message, i suspect LEA is still being used in the backend somewhere to fetch logs into the exporter&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont think related to your issue but worth being aware of&amp;nbsp;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;sk136992 - issues with A in cert pass phrase.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;risc&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 05 Oct 2018 05:00:04 GMT</pubDate>
    <dc:creator>Richard_Carson</dc:creator>
    <dc:date>2018-10-05T05:00:04Z</dc:date>
    <item>
      <title>R80.20 syslog - TLS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-syslog-TLS/m-p/32951#M6883</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Scenario: Sending events to remote syslog server encrypted (TLS) with log exporter.&lt;/P&gt;&lt;P&gt;Successfully receive clear text logs to remote server. Again TLS fails. Is there a configuration within the policy that need to enable (ie. rules, syslog server object, etc)?&amp;nbsp;&lt;/P&gt;&lt;P&gt;The remote syslog server is running syslog-ng 3.16.&amp;nbsp; Is this a cert issue?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Don't understand the reference about the LEA... LEA is not in use.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Getting the following errors:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 13px;"&gt;log_indexer 17057 4093631296]@cpmgmt01[4 Oct 15:44:13] Start reading 127.0.0.1:online logs [log] [1538636400] at position 53142&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 13px;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 13px;"&gt;[log_indexer 17057 4074761024]@&lt;SPAN style="color: #1f497d;"&gt;cpmgmt01&lt;/SPAN&gt;[4 Oct 15:44:13] Start reading 127.0.0.1:online logs [adtlog] [1538636400] at position 25&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 13px;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 13px;"&gt;[log_indexer 17057 4102024000]@&lt;SPAN style="color: #1f497d;"&gt;cpmgmt01&lt;/SPAN&gt;[4 Oct 15:44:18]&lt;STRONG&gt;&lt;EM style="text-decoration: underline;"&gt; LogFetcherLea::IsSubscribeLeaToDb This is not SmartEvent Device&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 13px;"&gt;[log_indexer 17057 4102024000]@&lt;SPAN style="color: #1f497d;"&gt;cpmgmt01&lt;/SPAN&gt;[4 Oct 15:44:18]&lt;STRONG&gt;&lt;EM style="text-decoration: underline;"&gt; LogFetcherLea::IsSubscribeLeaToDb This is not SmartEvent Device&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 13px;"&gt;[log_indexer 17057 4102024000]@&lt;SPAN style="color: #1f497d;"&gt;cpmgmt01&lt;/SPAN&gt;[4 Oct 15:44:18] Files read rate [log] : Current=0 Avg=0 MinAvg=0 Total=0 buffers (0/0/0/0)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 13px;"&gt;[log_indexer 17057 4102024000]@&lt;SPAN style="color: #1f497d;"&gt;cpmgmt01&lt;/SPAN&gt;[4 Oct 15:44:18] Sent&amp;nbsp; current: 0&amp;nbsp;&amp;nbsp; total: 0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 13px;"&gt;[log_indexer 17057 4121975616]@&lt;SPAN style="color: #1f497d;"&gt;cpmgmt01&lt;/SPAN&gt;[4 Oct 15:44:18] TcpTlsSender::MakeConnection call: certificate file: [/opt/CPrt-R80.20/log_exporter/targets/&lt;SPAN style="color: #1f497d;"&gt;syslogserver&lt;/SPAN&gt;/certs/log_exporter.p12] CA file: [/opt/CPrt-R80.20/log_exporter/targets/&lt;SPAN style="color: #1f497d;"&gt;syslogserver&lt;/SPAN&gt;/certs/RootCA.pem]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 13px;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 13px;"&gt;[log_indexer 17057 4121975616]@&lt;SPAN style="color: #1f497d;"&gt;cpmgmt01&lt;/SPAN&gt;[4 Oct 15:44:18] TcpTlsSender::MakeConnection: keyHolder initiated OK&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 13px;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 13px;"&gt;[log_indexer 17057 4121975616]@&lt;SPAN style="color: #1f497d;"&gt;cpmgmt01&lt;/SPAN&gt;[4 Oct 15:44:18] prefix: /opt/CPrt-R80.20/log_exporter/targets/&lt;SPAN style="color: #1f497d;"&gt;syslogserver&lt;/SPAN&gt;/certs/RootCA.pem cert: &lt;A href="mailto:Email=cyberdm@bt.com,CN=172.18.175.26,OU=BT"&gt;Email=&lt;SPAN style="color: #1f497d;"&gt;blah@blah.com&lt;/SPAN&gt;,CN=&lt;SPAN style="color: #1f497d;"&gt;10.10.10.145&lt;/SPAN&gt;,OU=BT&lt;/A&gt; ATM Certificate Authority,O=&lt;SPAN style="color: #1f497d;"&gt;Lab Plc&lt;/SPAN&gt;.,L=&lt;SPAN style="color: #1f497d;"&gt;Nowhere&lt;/SPAN&gt;,ST=&lt;SPAN style="color: #1f497d;"&gt;Nowhere&lt;/SPAN&gt;,C=US&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 13px;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 13px;"&gt;[log_indexer 17057 4121975616]@&lt;SPAN style="color: #1f497d;"&gt;cpmgmt01&lt;/SPAN&gt;[4 Oct 15:44:18] TcpTlsSender::MakeConnection: create new fwCert to CA succeeded&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 13px;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 13px;"&gt;[log_indexer 17057 4121975616]@&lt;SPAN style="color: #1f497d;"&gt;cpmgmt01&lt;/SPAN&gt;[4 Oct 15:44:18] TcpTlsSender::MakeConnection: create ckpSSLparams_New succeeded&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 13px;"&gt;[log_indexer 17057 4083153728]@&lt;SPAN style="color: #1f497d;"&gt;cpmgmt01&lt;/SPAN&gt;[4 Oct 15:44:18] Files read rate [adtlog] : Current=0 Avg=0 MinAvg=0 Total=0 buffers (0/0/0/0)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 13px;"&gt;[log_indexer 17057 4083153728]@&lt;SPAN style="color: #1f497d;"&gt;cpmgmt01&lt;/SPAN&gt;[4 Oct 15:44:18] Sent&amp;nbsp; current: 0&amp;nbsp;&amp;nbsp; average: 0 total: 0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 13px;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 13px;"&gt;[log_indexer 17057 4121975616]@&lt;SPAN style="color: #1f497d;"&gt;cpmgmt01&lt;/SPAN&gt;[4 Oct 15:44:18] &lt;EM style="text-decoration: underline;"&gt;&lt;STRONG&gt;TcpTlsSender::MakeConnection: ckpSSL_Connect failed error: unknown&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Oct 2018 03:03:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-syslog-TLS/m-p/32951#M6883</guid>
      <dc:creator>Ethan_Keaton</dc:creator>
      <dc:date>2018-10-05T03:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 syslog - TLS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-syslog-TLS/m-p/32952#M6884</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's entirely possible we are using LEA "under the covers" for parts of the functionality that Log Exporter is using--that's probably safe to ignore.&lt;/P&gt;&lt;P&gt;But I suspect it's an SSL error of sorts.&lt;/P&gt;&lt;P&gt;If it's a TLS/SSL negotiation issue, it should show up in a packet capture.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/migrated-users/15324"&gt;Yonatan Philip&lt;/A&gt;&amp;nbsp;might have some suggestions for debugging this also.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Oct 2018 04:52:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-syslog-TLS/m-p/32952#M6884</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-10-05T04:52:48Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 syslog - TLS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-syslog-TLS/m-p/32953#M6885</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are having similar issues with R80.10 log exporter to rsyslog, same ssl connect failed error - I have asked TAC how we can get more detailed output on the SSL connect as really this error message&amp;nbsp;does not provide enough detail.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Having tested with openssl s_client -connect, if i use a fully chained root CA pem file the handshake to the rsyslog server works fine. If i use this same CA cert file in the Log Exporter config then it fails to parse the CA cert file - doesnt seem to like a pem file with chained certs. If i use the intermediate cert as the CA file then LogExport does not complain but ssl connect fails.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In regards the LEA&amp;nbsp; message, i suspect LEA is still being used in the backend somewhere to fetch logs into the exporter&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont think related to your issue but worth being aware of&amp;nbsp;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;sk136992 - issues with A in cert pass phrase.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;risc&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Oct 2018 05:00:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-syslog-TLS/m-p/32953#M6885</guid>
      <dc:creator>Richard_Carson</dc:creator>
      <dc:date>2018-10-05T05:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 syslog - TLS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-syslog-TLS/m-p/32954#M6886</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry but TLS isn't my area of expertise. Please open a support case so&amp;nbsp;a relevant support engineer can look at the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Yonatan&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Oct 2018 02:16:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-syslog-TLS/m-p/32954#M6886</guid>
      <dc:creator>Yonatan_Philip</dc:creator>
      <dc:date>2018-10-08T02:16:26Z</dc:date>
    </item>
  </channel>
</rss>

