- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi,
From time to time (twice every month on avg), our management appliance doesn't receive any logs from our gateways.
We have 40+ gateways managed by our management appliance. Only solution we found so far was to reboot the management, and after that, it start to receive logs again.
Do you know the troubleshooting steps we could use to find out what's wrong next time it happens ?
Management has recently been upgraded to R81, most our gateways are either SMB or R80.30.
Thanks in advance.
Regards,
Antoine
The fwd process handles receiving the logs from all your gateways on TCP/257 and writing them to disk. If that process experiences difficulty logs can stop. Check the $FWDIR/log/fwd.elg file on the SMS for clues about what is wrong when the logs halt; you don't necessarily need to enable a debug on fwd to see useful logs in this file. In future if this happens again you don't need to reboot the entire SMS, just kill the fwd process on the SMS which will be restarted within 60 seconds by the Check Point Watchdog Dameon (cpwd). Unfortunately I've had to do this many times over the years to get logs moving again.
The cpstat -f log_server mg command is quite handy for getting a real-time look at which gateways are connected to the SMS's log server via TCP/257 and the log receive rate.
There are quite a few SK's about how to troubleshoot this, but this is probably the best one: sk38848: Practical troubleshooting steps for logging issues
The fwd process handles receiving the logs from all your gateways on TCP/257 and writing them to disk. If that process experiences difficulty logs can stop. Check the $FWDIR/log/fwd.elg file on the SMS for clues about what is wrong when the logs halt; you don't necessarily need to enable a debug on fwd to see useful logs in this file. In future if this happens again you don't need to reboot the entire SMS, just kill the fwd process on the SMS which will be restarted within 60 seconds by the Check Point Watchdog Dameon (cpwd). Unfortunately I've had to do this many times over the years to get logs moving again.
The cpstat -f log_server mg command is quite handy for getting a real-time look at which gateways are connected to the SMS's log server via TCP/257 and the log receive rate.
There are quite a few SK's about how to troubleshoot this, but this is probably the best one: sk38848: Practical troubleshooting steps for logging issues
Thanks, I'll check that next time we'll face the issue. Quite relieve to see I'm not the only one who faces that issue.
Actually, there is an old CP "trick" used for this that works every single time. So, in essence, here is what you do:
-create new CP host from the objects menu (NOT an actual basic regular host, but CP host that would let you enable logging etc)
-once you see a window to set it up, ONLY enable logging and put in same IP address of your management server and simply save it, thats it, install the database
-once done, change logging on your firewall objects to log that that new host and push policy
-what this does is simply "resets" logging mechanism and if that works (which Im positive it will), leave like that for few days and then change to regular management after (you can still keep that new host in there, wont hurt)
I had seen this work every single time for the last 10 years. If you want me to show you, message me privately, happy to give you an example of it via remote session.
Cheers!
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 16 | |
| 7 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY