- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi Team,
I am facing this weird issue; I upgraded my hardware from 4000 series to 6000 series and upgraded versions as well. My management server was already upgarded and recently I upgraded hardware of firewall as well as version from R77.30 to R80.40.
However after upgradation my logs are completely stopped and here is I am getting in fwd.elg
[FWD 17769]@xxx-CPFW_02[3 Sep 10:36:30] 10:36:30: srv_disconnected: change xx.xx.10.2 status to Status ERROR description: Log-Server Disconnected
log_connected: connect to '192.168.10.2' failed
[FWD 17769]@xxx-CPFW_02[3 Sep 10:37:35] 10:37:35: srv_disconnected: change xx.xx.10.2 status to Status ERROR description: Log-Server Disconnected
Nah - I resolved on my own. This was an issue with $FWDIR/conf/masters file and I observed that attribute was changed to +i
I changed to -i and rebooted the gws
Hi
Perhaps this might help (even if the issue seems a bit different):
Basically, perform Install Database on the Security Management Server (Log Servers)
Otherwise contact TAC
Thanks
Nah - I resolved on my own. This was an issue with $FWDIR/conf/masters file and I observed that attribute was changed to +i
I changed to -i and rebooted the gws
Would you mind please telling me what exact attribute that is? I have exact same errors in fwd.elg and logging is failing, but cant see any +i option in masters file...thanks in advance.
May be it could be something else for you. But to check attribute
lsattr $FWDIR/conf/masters
Also if you can check what are the contents of masters file?
I think you are probably right...below is what I get
lsattr $FWDIR/conf/masters
---------------- /opt/CPsuite-R81/fw1/conf/masters
Funny thing is, content was default mgmt name and logging was fine for a while, then it stopped with no changes...I ended up changing masters file to mgmt IP address in all fields and then logging started and worked for 2 weeks and then stopped again, so its a bit puzzling as to why this keeps happening.
That’s the immutable flag, a file attribute at the OS level.
It prevents the file from being overwritten.
Which that file is on policy install: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
Funny thing is, never had to do that sk before (at least from what I can remember), but followed it and also changed masters file to reflect mgmt IP and not the name and that worked. Whether that solution will last, remains to be seen : )
Hello, @Blason_R
One can be able to read binary files oneself?
Or is it necessary to scale these cases to TAC?
I have a “log-server disconnected” problem and I would like to know what is inside the files, without impacting the box services.
Is this possible?
[Expert@FWCP-LV:2]# grep -i "log-server disconnected" $FWDIR/log/fwd.elg*
Binary file /opt/CPsuite-R81.20/fw1/CTX/CTX00002/log/fwd.elg.5 matches
Binary file /opt/CPsuite-R81.20/fw1/CTX/CTX00002/log/fwd.elg.6 matches
Binary file /opt/CPsuite-R81.20/fw1/CTX/CTX00002/log/fwd.elg.7 matches
Binary file /opt/CPsuite-R81.20/fw1/CTX/CTX00002/log/fwd.elg.8 matches
[Expert@FWCP-LV:2]#
Thanks!
These files can be reviewed without impacting services.
.elg files are not supposed to be "binary" files, though...
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 25 | |
| 15 | |
| 13 | |
| 10 | |
| 6 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 2 |
Wed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY