Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Danny
MVP Platinum
MVP Platinum

Frequent WEB_API logins

Every 30 secs a WEB_API login session from 127.0.0.1 appears in SmartConsole > Manage & Settings > View Sessions
Any ideas or suggestions? Maybe something like sk179685?

api_login.png

0 Kudos
4 Replies
Amir_Senn
MVP Silver CHKP MVP Silver CHKP
MVP Silver CHKP

Could be any number of applications from CME to Infinity Portal which requires frequent checks with MGMT.

If this doesn't sound familiar I suggest going to audit logs and see if WEB_API does changes other than log in/out.

Kind regards, Amir Senn
0 Kudos
Don_Paterson
MVP Gold
MVP Gold

I've often been looking at that view and seen the WEB_API sessions pop up and disappear within a few seconds.

I just thought it must be a schedules job running in the background and did not look into it any further.

The SK is a bit vague.

I guess that with ATP and things like Cloud (CME and CloudGuard Controller) there is a need to have them visit the postgres database or the logs from time to time.

I see CloudGuard IaaS 'blade' logs in the audit logs, and I guess it's related. (Description: Mapping of Data Center)

But it looks like the SmartConsole is sending API calls (polling) in the background as long as it is connected.

I just started looking in api.elg and I see this:

My SmartConsole is connected from 10.1.1.201 and I am not using the API but in the log below you can see a show-cloud-services call.

api-elg.png 

The SmartConsole API tool API commands show as 127.0.0.1 and not localhost, showing a difference between the scheduled call and an admin's manual API call:

SmartConsole-admin-call.png

 

When I click on INFINTY SERVICES while doing a tail -F of api.elg I see a bit more activity and commands like show-cloud-services.

The command show-notifications shows up a lot and when I close SmartConsole it runs unsubscribe-notifications.

Then it generates some errors because the session doesn't exist and the the elg goes very quiet.

No new entries are added to the api.elg file until the SmartConsole is used agian (login) and then it gets new entries.

The WEB_API session appears in the View Sessions window regularly and corresponds with the show-cloud-services call but not all of them. It seems like it runs two or three show-cloud-services calls and then the session pops up for the next one and the log shows a logout command, but the next two or three commands still run alright.

I am using R82 JHFA T33 on a VM in the lab with no CloudGuard or Infinity Services connections. Isolated from that perspective.

Internet connected.

ATP is running on the two managed gateways (Cluster and single SG), as well as APPI, URLF, CA and IDA.

0 Kudos
Don_Paterson
MVP Gold
MVP Gold

Just to add. 

When working in Package repository there are a lot of log of entries in api.elg and when working with Central Deployment (SmartConsole used to upgrade or hot fix gateways) then there may be a WEB_API session that last longer than a few seconds.

0 Kudos
Danny
MVP Platinum
MVP Platinum

@Don_Paterson , @Amir_Senn ,

I checked api.elg and confirm that every 30 secs show-cloud-services is automatically triggered.
No CME, Infinity Portal, CDT or Package Repository is in use.
api.elg shows the same output as when I run the command manually:
web_api_show_cloud.png
This kind of distracting behaviour in SmartConsole is quite annoying, especially when many admins are working with SmartConsole and don't know what this is.

I checked if CloudGuard is enabled:

[Expert@Management:0]# cloudguard
CloudGuard IaaS is enabled and running

Usage:
 on             Enable CloudGuard IaaS
 off            Disable CloudGuard IaaS

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events