- Products
- Learn
- Local User Groups
- Partners
- More
Introduction to Lakera:
Securing the AI Frontier!
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi,
We have started to use 1530 gates to connect our external sites and i am having problems getting the logs to log server and i can't seem to find the correct SK so i'll try asking here.
We have 5200 gates as hub and 1530 as spokes, SIC is established between 1530 and logs/managament and working.
Under "External Log Servers" on 1530 it says "The appliance is managed by Check Point SmartConsole. Security Log Servers are configured in SmartConsole.".
Under Logs->Log Servers on the gateway object for 1530 in management has the logserver specified.
I can't see anything in logs that indicate what can be why logs are not sent to log server, the 1530 logs fine locally.
grateful for any pointers.
Tried R80.20.35 yet ? Both cited SKs are for R77.20.xx SMBs, so they are also valid for 1530... Only that $FWDIR/conf/masters is not used anymore in R80.20.xx Another tipp is sk66381 !
sk38848: Practical troubleshooting steps for logging issues
a simple first step - try install database on your management server.
tried installing database and restarts on both sides and no change found that connection on port 257 is stuck on SYN_SENT on the gateway will go from there.
Hi,
I don't see anything special here that might go wrong.
It should simply work.
Maybe the install database wasn’t done? Can you install DB and let us know?
tried installing DB no change
netstat -anp | grep -i -E "State|257" on the gate shows it is trying to connect to port 257 but what confuses me a bit is that it uses WAN adress as local for the gate and local adress as foreign to log server.
Everywhere i look on the 1530 gate it uses the WAN IP to the management but for the logs for some reason it uses the local IP.
Looks like a NAT issue - was SIC established with NATed SMS IP ? See sk103215 and sk108707 for such issues.
does not look like these SK applies to 1530 you can't change any IP manually in security management.
Looks like something is up with firmware R80.20.30 (992002285) as soon as i upgrade to that the gate uses local IP for log connection.
Or not, it is the reboot, on SIC initialization it uses external IP for logs but after reboot it uses local IP and fails.
Tried R80.20.35 yet ? Both cited SKs are for R77.20.xx SMBs, so they are also valid for 1530... Only that $FWDIR/conf/masters is not used anymore in R80.20.xx Another tipp is sk66381 !
sk66381 showed something that i did not noticed that i should have seen earlier, when initializing SIC i left it on send logs according to policy. Re-initialized SIC now with send logs to same IP and now it does not change to local IP after reboot.
The SK for R77 pointed to how to change this after the fact but need to do that on initialization that confused me.
Thanks for all the pointers!
found that log connection worked up until i upgraded the firmware on the 1530 gate last week, did factory default and after new SIC and policy push the log connection works again and this time netstat -anp | grep -i -E "State|257" shows that it connects to the log server via the external IP and not the local IP.
hi. we had the same issue with a centrally managed 1500 and 1400 series gateway.
We fixed it by following steps:
Nice info that option to change log IP was quite hidden good to know, we re-initialized SIC to change this in the wizard.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
13 | |
4 | |
3 | |
3 | |
3 | |
3 | |
2 | |
2 | |
2 | |
1 |
Thu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAThu 18 Sep 2025 @ 02:00 PM (EDT)
Bridge the Unmanaged Device Gap with Enterprise Browser - AmericasMon 22 Sep 2025 @ 03:00 PM (CEST)
Defending Hyperconnected AI-Driven Networks with Hybrid Mesh Security EMEAMon 22 Sep 2025 @ 02:00 PM (EDT)
Defending Hyperconnected AI-Driven Networks with Hybrid Mesh Security AMERThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAThu 18 Sep 2025 @ 02:00 PM (EDT)
Bridge the Unmanaged Device Gap with Enterprise Browser - AmericasMon 22 Sep 2025 @ 03:00 PM (CEST)
Defending Hyperconnected AI-Driven Networks with Hybrid Mesh Security EMEAAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY