Hi,
I am currently investigating a syslog issue and wanted to through in a post to see if more people have this or can reproduce this.
Setup
- Hardware: 2 Spark appliances (1575), version: R81.10.17 (996004653). Both are on different locations, both have a public WAN IP.
- firewall/access: NO VPN between them, port forward in FW1 to forward syslog from FW2 to specific internal system
- FW1: External Syslog server -> IP and port (UDP) in local subnet
- FW2: External Syslog server -> IP (WAN IP FW1) and port which is forwarded.
Observed behavior (from the syslog server):
- Basic setup and both FWs are submitting syslog traffic to the internal system (checked/observed from this internal system)
- After reboot FW1 (or other downtime), syslog resumes on FW1, syslog on FW2 stops and doesn't resume when connection is back again
- After a re-save of the External Syslog Server settings (without changes) on FW2, the syslog traffic resumes
note; I also observed this in versions R81.10.15 and R81.10.10.