Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
DominusRex23
Participant

Log Delivery Issue in ElasticXL Setup

Hi everyone,

We have a current setup here in ElasticXL where the gateway’s MGMT port is configured with IP 192.168.168.10, while the Smart-1 MGMT port uses 192.168.1.1. Both devices are connected to the core switch, and routing between them is properly configured. ICMP/ping tests confirm mutual reachability.

However, when we opened SmartConsole, no logs were visible. Insights showed that the management server was up and reachable from both firewalls. Under Device Information > Log Servers Connectivity, we saw a description indicating a connectivity problem.
To troubleshoot, we changed the gateway’s MGMT IP to 192.168.1.11, placing it in the same subnet as Smart-1. After this change, logs started appearing in SmartConsole as expected.

Can anyone confirm if this subnet alignment is a requirement for log delivery in ElasticXL? Is this an expected behavior?

edit: Smart-1 MGMT port is 192.168.1.1

0 Kudos
3 Replies
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

There's no requirement to have them in the same subnet. Did you have an explicit route out the of the cluster to 192.168.1.0/24 that would use the magg interface or was it just that default route? 

0 Kudos
Martin_Raska
Advisor
Advisor

tcpdump here is your best friend and double check the routing via magg interface.

0 Kudos
the_rock
MVP Platinum
MVP Platinum

I will add maybe doing fw monitor too may help.

Best,
Andy
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events