- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- No Traffic Logs after Take 121 + Smack Update
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No Traffic Logs after Take 121 + Smack Update
I upgraded my management station, my log server and my two prod 23500s with the Take 121 and Smack Updates and now I no longer receive traffic logs. From the firewall I get these errors.
[Expert@CP-PROD-02:0]# fw log
Error in loading unification scheme
tail -f /opt/CPsuite-R80/fw1/log/fwd.elg
CKlogUnifier::buffToUniFragment: error: unifier has not completed initialization yet
FwKluProcessLogEx: fail to convert klog buffer to unified fragment
Other firewalls not upgraded still send and show traffic logs.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
So, went back over everything and got it working. Replacing the log_unification_scheme.C file was the fix. The problem is I didnt set the permissions properly after replacing the file. So, cpstop, upload the file, chmod 770, cpstart . The file I am using that is working has a date of 12/14/2017 12:29PM and is 16KB in size. The files I replaced were missing some sections. No idea why.
Support had never seen this problem on a gateway before, only a management station. Anyway, case closed.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Looks like the error from sk106391 - did you try the procedure from the sk yet ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks but that is from the management server. This error is happening on the gateway.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just to add some more, bizarre info:
The firewalls are sending some non-traffic related logs. Identity Awareness , Virus/Bot traffic , etc, just no traffic logs.
Thanks,
Justin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I recommend engaging with the TAC so we can look into this.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks, I do have a case open. Was escalated to the high end team. They suggested I try to replace the log_unification.C file with one from before take 121. That didn't work.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The only time the logging works now is when i got back to the original release of R80.10 . If I apply any fix packs device logging breaks and an fw log command returns the below error.
[Expert@CP-PROD-02:0]# fw log
Error in loading unification scheme
So now I have the unfortunate option of running without logs or running without fix packs.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just an update, there is some indication this problem is tied to the original .iso build 421 . If you used that build I'd recommend staying away from Take 121 for now.
Testing this theory now, more to come.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I rebuilt one of the less important firewalls with .iso build T462. I was able to patch up to the latest version while logging continued to function. I don't know if the simple rebuild fixed my issue or if the root cause is related to build 421.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Support has told me they can do no more for me. The fix is for me to manually rebuild 6 gateways. I've done this. The problem persists on 3 of the 6 gateways.
Justin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
So, went back over everything and got it working. Replacing the log_unification_scheme.C file was the fix. The problem is I didnt set the permissions properly after replacing the file. So, cpstop, upload the file, chmod 770, cpstart . The file I am using that is working has a date of 12/14/2017 12:29PM and is 16KB in size. The files I replaced were missing some sections. No idea why.
Support had never seen this problem on a gateway before, only a management station. Anyway, case closed.
