- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Happy Friday everyone.
Always running low on space on our current log server, so i've provisioned a new one with 40T of space and trying to get it receiving logs. This server is on the inside of my network and privately addressed, so i need the logs to traverse the VPN path.
Management is R82 and gateways are R81.20.
Per the guide, the salient implied rules file is: /opt/CPR8120CMP-R82/lib/implied_rules.def
So i made this change : /* #define ENABLE_FWD_LOG */
After pushing policy to a gateway the logging continues to go out on the implied rule 0.
Any ideas on what i've missed here would be appreciate.
Thanks.
with the help of a tac case, yeah. I'm "pretty" sure the order that i did was: modify implied rules file \ installed database only to the new log server \ and then pushed policy to the gateway.
Tac had me install database on everything - 2 log servers and management...and then push policy again. Started working immediately.
That's why we all have support!
If you go to smart console, security policy -> implied rules, see if its logged or not, you can uncheck it there.
Andy
I attached short video of what I meant. If this does not work, and what you tried failed as well, I would definitely verify with TAC.
Andy
Thanks Andy. I reread my initial post and i probably wasn't very clear. I don't want to change the actually logging of the traffic that matches the implied rules. I want to change the way the gateway communicates with the its log server - the actual tcp/257 traffic. And i only want to change this behavior for logging since i have logs and management separate, the normal management <-> gateway control connections would stay the same.
Per what i read and what i've done in the past for LDAP, this implied rule setting should control that.
- /* #define ENABLE_FWD_LOG */
I guess i'll open a tac on monday.
Have a great weekend.
I would get an official TAC response, agreed.
Have a good 1, as kids woukd say these days 🙂
Andy
with the help of a tac case, yeah. I'm "pretty" sure the order that i did was: modify implied rules file \ installed database only to the new log server \ and then pushed policy to the gateway.
Tac had me install database on everything - 2 log servers and management...and then push policy again. Started working immediately.
That's why we all have support!
Great news!
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY