Hi,
R80.30 environment. SG cluster is not sending logs to SMS.
Steps that I have done in troubleshooting:
- Installed database in SmartConsole.
- Installed policy several times.
- Changed the SG to log locally, installed policy and then reverted to sending logs again to SMS in SmartConsole.
- Rebooted the cluster that don’t send logs to the SMS
- Disk space is checked on SMS and is fine.
- Checked that security gateway is configured to send logs to SMS in SmartConsole.
- SIC communication is fine and communicating.
- Ping from SMS to SG works fine. The other way too.
- Checked that the SMS is listening on port 257. No connection from the cluster SG seen there.
- Checked if any logs are coming from the SG to the SMS on port 257 with tcpdump on the interface. No logs there.
- The active firewall log file fw.log is growing on the SG. Checked with the command watch -d -n 2 "ls -l $FWDIR/log/fw.log"
- Checked the masters file on the SG and it is set to log to the SMS
So are there anymore suggestions in troubleshooting this issue? Could it be that the last step (that I didn't do), the active firewall log file fw.log might be corrupted on the SG?