- Products
- Learn
- Local User Groups
- Partners
- More
Maestro Masters
Round Table session with Maestro experts
Maestro - Seeing these events in Audit Logs
Delete Object - Deleted IP Address 192.0.2.2 on logical interface (Sync).
Set Object - Logical Interface (Sync) is configured with IP Address 192.0.2.2/24
Seems to be occurring in the evenings several times per week and the two events will repeat multiple times and then subside. There are no reports of any traffic issues during these times.
MHO is R81.20 HF-92 and SGMs are R81.20 HF-76
The events can also be seen in a SmartLog search using criteria - objectname:Interfaces
Any clues in /var/log/messages during issue? Does this event occurs during policy push?
Maybe quick hardware / port check of the Sync port, to make sure it works as it should:
https://support.checkpoint.com/results/sk/sk180812
April 15, 2025
Detailed analysis shows these may be related to reboots, although not initially confirmed as a scheduled reboot but an unscheduled reboot which was more so related to an HFA update. More to come as the Audit logs showing details for 'Deleted IP Address 192.0.2.2 on logical interface (Sync)' are well preserved but not always the case with message files and cpuse install details.
April 17, 2025.
We can positively say that this error is directly related to SGM reboots. So now we know who, what, where and when but 'why' is still not determined.
JHF installation can ofcourse change config on the unit itself. So question is, does this only happen during JHF install? Or every reboot? Is there any impact?
According to our records it occurs whenever there is a reboot and the specific 192.0.2.x IP address in the audit logs would correlate to the Sync IP address of the associated SGM being rebooted. Because reboots and/or HFA installs are 'scheduled' and performed off-hours, there has not been any reported impacts. I also suspect that with Maestro's SGM load-balancing, then there would most likely never be a report of an outage. That is, unless all SGM's were being rebooted and/or upgraded at the same time and in that case, there would certainly be a scheduled outage. We are still investigating the 'why' factor. More to come....
8/12/25 - Update received from TAC, there is a fix coming, no ETA at this time but the fix id is PMTR-116320.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
18 | |
3 | |
2 | |
2 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 |
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY