<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Logs from 1530 to log server in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-from-1530-to-log-server/m-p/132601#M5960</link>
    <description>&lt;P&gt;hi. we had the same issue with a centrally managed 1500 and 1400 series gateway.&lt;/P&gt;&lt;P&gt;We fixed it by following steps:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;connect to gateway via web ui&lt;/LI&gt;&lt;LI&gt;open Home &amp;gt; Security Management&lt;/LI&gt;&lt;LI&gt;on "Security Management Server" click "test connection"&lt;/LI&gt;&lt;LI&gt;After test click on the IP Address&lt;/LI&gt;&lt;LI&gt;in new window tick the checkbox "Alaways use the following IP address to connect to your Security Managament Server"&lt;/LI&gt;&lt;LI&gt;in Address there should be your management IP&lt;/LI&gt;&lt;LI&gt;then select "Send logs to" and also enter the management IP&lt;/LI&gt;&lt;LI&gt;click apply, maybe reboot.&lt;/LI&gt;&lt;/UL&gt;</description>
    <pubDate>Tue, 26 Oct 2021 09:19:48 GMT</pubDate>
    <dc:creator>tspunkt</dc:creator>
    <dc:date>2021-10-26T09:19:48Z</dc:date>
    <item>
      <title>Logs from 1530 to log server</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-from-1530-to-log-server/m-p/132044#M5930</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have started to use 1530 gates to connect our external sites and i am having problems getting the logs to log server and i can't seem to find the correct SK so i'll try asking here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have 5200 gates as hub and 1530 as spokes, SIC is established between 1530 and logs/managament and working.&lt;/P&gt;&lt;P&gt;Under "External Log Servers" on 1530 it says "&lt;SPAN&gt;The appliance is managed by Check Point SmartConsole.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Security Log Servers are configured in SmartConsole.".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Under Logs-&amp;gt;Log Servers on the gateway object for 1530 in management has the logserver specified.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't see anything in logs that indicate what can be why logs are not sent to log server, the 1530 logs fine locally.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;grateful for any pointers.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 08:08:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-from-1530-to-log-server/m-p/132044#M5930</guid>
      <dc:creator>Marcus_Halmsjo</dc:creator>
      <dc:date>2021-10-19T08:08:45Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from 1530 to log server</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-from-1530-to-log-server/m-p/132049#M5931</link>
      <description>&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk38848&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;sk38848: Practical troubleshooting steps for logging issues&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 08:38:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-from-1530-to-log-server/m-p/132049#M5931</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-10-19T08:38:27Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from 1530 to log server</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-from-1530-to-log-server/m-p/132056#M5934</link>
      <description>&lt;P&gt;a simple first step - try install database on your management server.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 08:51:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-from-1530-to-log-server/m-p/132056#M5934</guid>
      <dc:creator>Peter_Lyndley</dc:creator>
      <dc:date>2021-10-19T08:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from 1530 to log server</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-from-1530-to-log-server/m-p/132067#M5936</link>
      <description>&lt;P&gt;tried installing database and restarts on both sides and no change found that connection on port 257 is stuck on SYN_SENT on the gateway will go from there.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 09:12:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-from-1530-to-log-server/m-p/132067#M5936</guid>
      <dc:creator>Marcus_Halmsjo</dc:creator>
      <dc:date>2021-10-19T09:12:29Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from 1530 to log server</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-from-1530-to-log-server/m-p/132071#M5938</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I don't see anything special here that might go wrong.&lt;/P&gt;
&lt;P&gt;It should simply work.&lt;/P&gt;
&lt;P&gt;Maybe the install database wasn’t done? Can you install DB and let us know?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 09:44:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-from-1530-to-log-server/m-p/132071#M5938</guid>
      <dc:creator>Ido_Shoshana</dc:creator>
      <dc:date>2021-10-19T09:44:00Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from 1530 to log server</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-from-1530-to-log-server/m-p/132076#M5939</link>
      <description>&lt;P&gt;tried installing DB no change&lt;/P&gt;&lt;P&gt;netstat -anp | grep -i -E "State|257" on the gate shows it is trying to connect to port 257 but what confuses me a bit is that it uses WAN adress as local for the gate and local adress as foreign to log server.&lt;/P&gt;&lt;P&gt;Everywhere i look on the 1530 gate it uses the WAN IP to the management but for the logs for some reason it uses the local IP.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 09:59:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-from-1530-to-log-server/m-p/132076#M5939</guid>
      <dc:creator>Marcus_Halmsjo</dc:creator>
      <dc:date>2021-10-19T09:59:39Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from 1530 to log server</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-from-1530-to-log-server/m-p/132102#M5940</link>
      <description>&lt;P&gt;found that log connection worked up until i upgraded the firmware on the 1530 gate last week, did factory default and after new SIC and policy push the log connection works again and this time&amp;nbsp;netstat -anp | grep -i -E "State|257" shows that it connects to the log server via the external IP and not the local IP.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 11:39:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-from-1530-to-log-server/m-p/132102#M5940</guid>
      <dc:creator>Marcus_Halmsjo</dc:creator>
      <dc:date>2021-10-19T11:39:56Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from 1530 to log server</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-from-1530-to-log-server/m-p/132104#M5941</link>
      <description>&lt;P&gt;Looks like a NAT issue - was SIC established with NATed SMS IP ? See&amp;nbsp;&lt;SPAN&gt;sk103215 and&amp;nbsp;sk108707 for such issues.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 11:57:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-from-1530-to-log-server/m-p/132104#M5941</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-10-19T11:57:33Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from 1530 to log server</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-from-1530-to-log-server/m-p/132110#M5942</link>
      <description>&lt;P&gt;does not look like these SK applies to 1530 you can't change any IP manually in security management.&lt;/P&gt;&lt;P&gt;Looks like something is up with firmware&amp;nbsp;R80.20.30 (992002285) as soon as i upgrade to that the gate uses local IP for log connection.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 12:53:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-from-1530-to-log-server/m-p/132110#M5942</guid>
      <dc:creator>Marcus_Halmsjo</dc:creator>
      <dc:date>2021-10-19T12:53:36Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from 1530 to log server</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-from-1530-to-log-server/m-p/132113#M5943</link>
      <description>&lt;P&gt;Or not, it is the reboot, on SIC initialization it uses external IP for logs but after reboot it uses local IP and fails.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 13:06:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-from-1530-to-log-server/m-p/132113#M5943</guid>
      <dc:creator>Marcus_Halmsjo</dc:creator>
      <dc:date>2021-10-19T13:06:30Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from 1530 to log server</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-from-1530-to-log-server/m-p/132116#M5944</link>
      <description>&lt;P&gt;Tried&amp;nbsp;&lt;SPAN&gt;R80.20.35 yet ? Both cited SKs are for R77.20.xx SMBs, so they are also valid for 1530... Only that&amp;nbsp;&lt;EM&gt;$FWDIR/conf/masters&amp;nbsp;&lt;/EM&gt;is not used anymore in R80.20.xx Another tipp is&amp;nbsp;sk66381 !&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 13:56:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-from-1530-to-log-server/m-p/132116#M5944</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-10-19T13:56:30Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from 1530 to log server</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-from-1530-to-log-server/m-p/132125#M5945</link>
      <description>&lt;P&gt;&lt;SPAN&gt;sk66381 showed something that i did not noticed that i should have seen earlier, when initializing SIC i left it on send logs according to policy. Re-initialized&amp;nbsp;SIC now with send logs to same IP and now it does not change to local IP after reboot.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The SK for R77 pointed to how to change this after the fact but need to do that on initialization that confused me.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks for all the pointers!&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 14:16:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-from-1530-to-log-server/m-p/132125#M5945</guid>
      <dc:creator>Marcus_Halmsjo</dc:creator>
      <dc:date>2021-10-19T14:16:26Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from 1530 to log server</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-from-1530-to-log-server/m-p/132601#M5960</link>
      <description>&lt;P&gt;hi. we had the same issue with a centrally managed 1500 and 1400 series gateway.&lt;/P&gt;&lt;P&gt;We fixed it by following steps:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;connect to gateway via web ui&lt;/LI&gt;&lt;LI&gt;open Home &amp;gt; Security Management&lt;/LI&gt;&lt;LI&gt;on "Security Management Server" click "test connection"&lt;/LI&gt;&lt;LI&gt;After test click on the IP Address&lt;/LI&gt;&lt;LI&gt;in new window tick the checkbox "Alaways use the following IP address to connect to your Security Managament Server"&lt;/LI&gt;&lt;LI&gt;in Address there should be your management IP&lt;/LI&gt;&lt;LI&gt;then select "Send logs to" and also enter the management IP&lt;/LI&gt;&lt;LI&gt;click apply, maybe reboot.&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Tue, 26 Oct 2021 09:19:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-from-1530-to-log-server/m-p/132601#M5960</guid>
      <dc:creator>tspunkt</dc:creator>
      <dc:date>2021-10-26T09:19:48Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from 1530 to log server</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-from-1530-to-log-server/m-p/132621#M5961</link>
      <description>&lt;P&gt;Nice info that option to change log IP was quite hidden good to know, we re-initialized SIC to change this in the wizard.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Oct 2021 11:33:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-from-1530-to-log-server/m-p/132621#M5961</guid>
      <dc:creator>Marcus_Halmsjo</dc:creator>
      <dc:date>2021-10-26T11:33:11Z</dc:date>
    </item>
  </channel>
</rss>

