<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: action:Key Install Missing in SmartLog for Quantum Spark, am i crazy? in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/action-Key-Install-Missing-in-SmartLog-for-Quantum-Spark-am-i/m-p/221360#M11078</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;investigation by TAC is still ongoing, with not much output so far.&lt;BR /&gt;Iam running all appliances which do not show "Action:Key Install" logs, on:&amp;nbsp;&lt;STRONG&gt;R81.10.10 (996002945)&lt;/STRONG&gt;&lt;BR /&gt;and one working one on:&amp;nbsp;&lt;STRONG&gt;R81.10.08 (996001608)&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;TAC advised me to downgrade one to: &lt;STRONG&gt;R81.10.08 (996001750).&lt;BR /&gt;&lt;/STRONG&gt;Iam not happy with downgrading. Because if&amp;nbsp;R81.10.08 (996001750) makes it work, TAC will close the ticket and when we upgrade to R81.10.10 again in the future, the issue could strike again, its just delaying ...&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;is anybody running&amp;nbsp;R81.10.08 (996001750) and still see "action:Key Install" in the log?&lt;/P&gt;</description>
    <pubDate>Fri, 19 Jul 2024 06:55:50 GMT</pubDate>
    <dc:creator>Thomas_Eichelbu</dc:creator>
    <dc:date>2024-07-19T06:55:50Z</dc:date>
    <item>
      <title>action:Key Install Missing in SmartLog for Quantum Spark, am i crazy?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/action-Key-Install-Missing-in-SmartLog-for-Quantum-Spark-am-i/m-p/219313#M10968</link>
      <description>&lt;P&gt;Hello team,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;i am wondering how this is possible.&lt;BR /&gt;i have a bunch of Quantum Sparks 1535 running, latest firmware "fw1_vx_dep_R81_10_10_996002945.img"&lt;BR /&gt;when i search in SmartLog for VPN activity i see no more &lt;STRONG&gt;"action:KeyInstall" and origin:GATEWAY.&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;for Full GAiA yes of course ... this still works.&lt;BR /&gt;but Quantum Spark, no.&lt;/P&gt;
&lt;P&gt;take a look:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NO_LOG.PNG" style="width: 700px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26555i2445AA44D04D4048/image-size/large?v=v2&amp;amp;px=999" role="button" title="NO_LOG.PNG" alt="NO_LOG.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;yes sure logging works!&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SOME_LOG.png" style="width: 845px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26556i0501AD7302D5E954/image-size/large?v=v2&amp;amp;px=999" role="button" title="SOME_LOG.png" alt="SOME_LOG.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;so i suspect with some kind of firmware version this stopped to work.&lt;BR /&gt;with all my 1430 running this works just fine ...&lt;BR /&gt;i also saw this on other customer running Quantum Spark 15XX and&amp;nbsp;"fw1_vx_dep_R81_10_10_996002945.img" or earlier ...&lt;BR /&gt;&lt;BR /&gt;what is going on here?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2024 18:59:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/action-Key-Install-Missing-in-SmartLog-for-Quantum-Spark-am-i/m-p/219313#M10968</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2024-07-01T18:59:50Z</dc:date>
    </item>
    <item>
      <title>Re: action:Key Install Missing in SmartLog for Quantum Spark, am i crazy?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/action-Key-Install-Missing-in-SmartLog-for-Quantum-Spark-am-i/m-p/219331#M10970</link>
      <description>&lt;P&gt;Maybe this is usefull&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/SMB_R81.10.X/CLI/EN/Content/Topics/set-vpn-site-to-site-log-vpn-successful-key-exchange.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/SMB_R81.10.X/CLI/EN/Content/Topics/set-vpn-site-to-site-log-vpn-successful-key-exchange.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Not sure if it works if it is central mgmt.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2024 21:23:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/action-Key-Install-Missing-in-SmartLog-for-Quantum-Spark-am-i/m-p/219331#M10970</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-07-01T21:23:33Z</dc:date>
    </item>
    <item>
      <title>Re: action:Key Install Missing in SmartLog for Quantum Spark, am i crazy?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/action-Key-Install-Missing-in-SmartLog-for-Quantum-Spark-am-i/m-p/219349#M10973</link>
      <description>&lt;P&gt;Hello Lesley,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;oh thank you very much to enlighten me ... lets check my (default) values&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;XXXXXXX&amp;gt; show vpn site-to-site advanced-settings&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;sync-sa-with-other-cluster-members:200000&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;period-before-crl-valid: 7200&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;delete-tunnel-sas-on-tt-fail: true&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;harmony-connect-residency:&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;udp-encapsulation-for-firewalls-and-proxies:true&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;copy-diff-serv-from-ipsec-packet:false&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;dpd-triggers-new-ike-negotiation:true&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;tunnel-test-from-internal: false&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;outgoing-rulebase-match: false&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;harmony-connect-ha-timeout-sec:30&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;ike-dos-protection-known-sites:none&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;enable-link-selection: true&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;limit-open-sas: 20&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;is-static-misp-role: false&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;copy-diff-serv-to-ipsec-packet:true&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;keep-dont-fragment-flag-on-packet:false&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;vpn-down-summary-interval: 1_Hour&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;period-after-crl-not-valid: 1800&lt;/EM&gt;&lt;EM&gt;maximum-concurrent-vpn-tunnels:10000&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;log-vpn-packet-handling-error&lt;/STRONG&gt;&lt;/EM&gt;&lt;EM&gt;&lt;STRONG&gt;s:log&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;life-sign-transmitter-interval:10&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;delete-ike-sas-from-a-dead-peer:true&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;vpn-tunnel-sharing: subnets&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;vpn-configuration-and-key-exchange-errors:log&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;ikev2-key-type: KEY_ID&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;reply-from-incoming-interface:false&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;bypass-psl-inspection: false&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;resolver-Session-interval: 25&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;no-local-dns-encrypt: false&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;is-admin-access-agnostic: true&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;keep-ikesa-keys: auto-mode&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;vpn-down-max-notification: 5&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;life-sign-timeout: 120&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;is-Passthrough-Active: false&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;reply-from-same-ip: true&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;collect-hb-monitoring-info: true&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;local-conns-from-internal: false&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;ike-dos-protection-unknown-sites:none&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;vpn-dns-resolver-interval: 30&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;harmony-connect-check-branch-used:false&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;maximum-concurrent-ike-n&lt;/EM&gt;&lt;EM&gt;egotiations:200&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;STRONG&gt;&lt;EM&gt;log-vpn-outgoing-link: none&lt;/EM&gt;&lt;/STRONG&gt;&lt;EM&gt;&lt;STRONG&gt;permanent-tunnel-down-track: log&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;permanent-tunnel-up-track: log&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;log-vpn-successful-key-exchange:log&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;log-notification-for-administrative-actions:log&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;timeout-for-an-rdp-packet-reply:10&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;check-validity-of-ipsec-reply-packets:false&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;perform-ike-using-cluster-ip: true&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;harmony-connect-check-subnet: false&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;ike-use-largest-possible-subnets:true&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;no-local-conns-encrypt: false&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;delete-ipsec-sas-on-ikes-delete:false&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;so yes it seems all the required log actions are set to true and always on true by default .. .nonetheless i have no logs.&lt;BR /&gt;so if the log action is set to log, but it doesnt log, i consider this a bug.&lt;BR /&gt;at least iam happy, removing vital logs is not made on purpose... i was afraid Check Point was giving way to the cancel culture by avoiding unfriendly logs!&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2024 05:30:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/action-Key-Install-Missing-in-SmartLog-for-Quantum-Spark-am-i/m-p/219349#M10973</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2024-07-02T05:30:23Z</dc:date>
    </item>
    <item>
      <title>Re: action:Key Install Missing in SmartLog for Quantum Spark, am i crazy?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/action-Key-Install-Missing-in-SmartLog-for-Quantum-Spark-am-i/m-p/219351#M10974</link>
      <description>&lt;P&gt;Probably a bug, I don't see this with centrally managed Spark running lower versions than R81.10.10 - which by the way is not yet recommended as per sk179615.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2024 05:37:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/action-Key-Install-Missing-in-SmartLog-for-Quantum-Spark-am-i/m-p/219351#M10974</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2024-07-02T05:37:04Z</dc:date>
    </item>
    <item>
      <title>Re: action:Key Install Missing in SmartLog for Quantum Spark, am i crazy?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/action-Key-Install-Missing-in-SmartLog-for-Quantum-Spark-am-i/m-p/219357#M10975</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;yes TAC case opened ... lets see what we find out.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2024 07:09:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/action-Key-Install-Missing-in-SmartLog-for-Quantum-Spark-am-i/m-p/219357#M10975</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2024-07-02T07:09:04Z</dc:date>
    </item>
    <item>
      <title>Re: action:Key Install Missing in SmartLog for Quantum Spark, am i crazy?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/action-Key-Install-Missing-in-SmartLog-for-Quantum-Spark-am-i/m-p/221360#M11078</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;investigation by TAC is still ongoing, with not much output so far.&lt;BR /&gt;Iam running all appliances which do not show "Action:Key Install" logs, on:&amp;nbsp;&lt;STRONG&gt;R81.10.10 (996002945)&lt;/STRONG&gt;&lt;BR /&gt;and one working one on:&amp;nbsp;&lt;STRONG&gt;R81.10.08 (996001608)&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;TAC advised me to downgrade one to: &lt;STRONG&gt;R81.10.08 (996001750).&lt;BR /&gt;&lt;/STRONG&gt;Iam not happy with downgrading. Because if&amp;nbsp;R81.10.08 (996001750) makes it work, TAC will close the ticket and when we upgrade to R81.10.10 again in the future, the issue could strike again, its just delaying ...&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;is anybody running&amp;nbsp;R81.10.08 (996001750) and still see "action:Key Install" in the log?&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2024 06:55:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/action-Key-Install-Missing-in-SmartLog-for-Quantum-Spark-am-i/m-p/221360#M11078</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2024-07-19T06:55:50Z</dc:date>
    </item>
    <item>
      <title>Re: action:Key Install Missing in SmartLog for Quantum Spark, am i crazy?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/action-Key-Install-Missing-in-SmartLog-for-Quantum-Spark-am-i/m-p/222134#M11096</link>
      <description>&lt;P&gt;wow,&amp;nbsp; finally TAC made it work ..&lt;BR /&gt;iam quite ashamed by this solution, perhaps rebooting the appliance would also have helped &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;run:&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;vpn iked disable&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR clear="none" /&gt;&lt;STRONG&gt;&lt;EM&gt;sfwd_restart&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;and Key Install Logs are back!&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2024 12:33:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/action-Key-Install-Missing-in-SmartLog-for-Quantum-Spark-am-i/m-p/222134#M11096</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2024-07-29T12:33:26Z</dc:date>
    </item>
    <item>
      <title>Re: action:Key Install Missing in SmartLog for Quantum Spark, am i crazy?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/action-Key-Install-Missing-in-SmartLog-for-Quantum-Spark-am-i/m-p/227347#M11441</link>
      <description>&lt;P&gt;Hello folks,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;as TAC promised, the new SMB firmware R81.10.10.15 finally fixed this issue!&lt;BR /&gt;Key Install Log is back now!&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk182438" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk182438&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2024 09:39:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/action-Key-Install-Missing-in-SmartLog-for-Quantum-Spark-am-i/m-p/227347#M11441</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2024-09-20T09:39:44Z</dc:date>
    </item>
    <item>
      <title>Re: action:Key Install Missing in SmartLog for Quantum Spark, am i crazy?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/action-Key-Install-Missing-in-SmartLog-for-Quantum-Spark-am-i/m-p/228717#M11534</link>
      <description>&lt;P&gt;Hello a new update ...&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk182438" target="_blank" rel="noopener"&gt;R81.10.15&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;Build 996003913 is still not 100% working, it still needs a&amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;vpn iked disable&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR clear="none" /&gt;&lt;STRONG&gt;&lt;EM&gt;sfwd_restart&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;/SPAN&gt;to show key Install logs. but this action at least survives any further reboots.&lt;BR /&gt;&lt;BR /&gt;TAC gave me a special version, which is not yet available:&amp;nbsp;fw1_vx_dep_R81_10_15_996003920.img&lt;BR /&gt;this really helped!&lt;/P&gt;
&lt;P&gt;now its mission accomplished!&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2024 08:10:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/action-Key-Install-Missing-in-SmartLog-for-Quantum-Spark-am-i/m-p/228717#M11534</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2024-10-02T08:10:00Z</dc:date>
    </item>
  </channel>
</rss>

