- Products
- Learn
- Local User Groups
- Partners
- More
The Great Exposure Reset
24 February 2026 @ 5pm CET / 11am EST
CheckMates Fest 2026
Watch Now!AI Security Masters
Hacking with AI: The Dark Side of Innovation
CheckMates Go:
CheckMates Fest
I'm trying to follow sk146112 however my masters file will not update . is there any way i can recreate this file ?
I've tried everything . please advise.
Ruining R81.10 Take 81
HI @PhoneBoy
Because my MDM and MDLM are external to the gateway in this scenario.
We are using static NAT on the mgmt. and LOG objects.
The gateway is sending logs tcp/257 to the private ip of the MDM and MDLM. This is not going to ever work . It HAS to be the NAT'd IP address (Public IP)
That being said i got it working . I created a dummy object in smart consoled and used that for the logging destination . its working .
You need to follow sk at the bottom.
$FWDIR/conf/masters file on Security Gateway was modified manually. However, this file is overwritten during each policy installation.
just want to say that it does not appear that my masters file is being overwritten ....
ive modified the masters file but when i run the following for example "tcpdump -nnei any port 257"
it does not reflect these changes
i tried to delete the file but it does not allow me to do that
The link I gave gives steps to preserve manual changes. Isnt that what you want to achieve?
that is working. i have no problems with the masters file being overwritten
the problem is that its still not working .
Sorry, not trying to be difficult, but what is NOT working? Firewalls are not logging to mgmt server or something else? Can you provide content of masters file?
When you say "tried everything" what precise steps did you take?
What result did you expect?
What happened instead?
Pretty sure modifying this file requires a cprestart, or at the very least a policy install action.
A better question is: why are you modifying this file in the first place?
There is generally ways to accomplish what this file does via SmartConsole configuration.
HI @PhoneBoy
Because my MDM and MDLM are external to the gateway in this scenario.
We are using static NAT on the mgmt. and LOG objects.
The gateway is sending logs tcp/257 to the private ip of the MDM and MDLM. This is not going to ever work . It HAS to be the NAT'd IP address (Public IP)
That being said i got it working . I created a dummy object in smart consoled and used that for the logging destination . its working .
The Dummy Object workaround used to be documented here: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
It is still listed in the internal comments, but it shouldn't be necessary in current versions...
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 26 | |
| 22 | |
| 10 | |
| 9 | |
| 8 | |
| 8 | |
| 7 | |
| 7 | |
| 6 | |
| 5 |
Thu 19 Feb 2026 @ 03:00 PM (EST)
Americas Deep Dive: Check Point Management API Best PracticesTue 24 Feb 2026 @ 11:00 AM (EST)
Under The Hood: CloudGuard Network Security for Azure Virtual WANThu 19 Feb 2026 @ 03:00 PM (EST)
Americas Deep Dive: Check Point Management API Best PracticesTue 24 Feb 2026 @ 11:00 AM (EST)
Under The Hood: CloudGuard Network Security for Azure Virtual WANAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY