Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Arturxr
Explorer

ISP Crash Analysis

Hello, is there a mechanism for analyzing provider outages? We had a provider switch, but we can't find a way to track it for incident investigation. The logs show that the NAT changed and that's all.

0 Kudos
11 Replies
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

Of the below which technology are you leveraging in this context?

  • Dynamic Routing
  • ISP Redundancy
  • SD-WAN
  • Other?

CCSM R77/R80/ELITE
0 Kudos
Arturxr
Explorer

  • ISP Redundancy
0 Kudos
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

0 Kudos
Arturxr
Explorer

If I understand correctly, we don't have any of this configured and we won't be able to view any logs of the incident that occurred?

0 Kudos
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

You can also review the contents of /var/log/messages or /var/log/messages.n to see if there a clues recorded there in lieu of the above.

CCSM R77/R80/ELITE
0 Kudos
Arturxr
Explorer

And another question, if I set the Logs parameter in the ISP Redundancy settings, where will these logs be displayed?

0 Kudos
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

SmartView/SmartConsole

CCSM R77/R80/ELITE
0 Kudos
the_rock
MVP Platinum
MVP Platinum

You can also search by blade in the logs, though not sure if isp redundancy would be there, as its not technically a blade. 

Best,
Andy
0 Kudos
the_rock
MVP Platinum
MVP Platinum

Hey mate,

Any luck with this?

Best,
Andy
0 Kudos
Arturxr
Explorer


We haven't been able to figure out why the ISP switches are happening yet. We set the "LOG" parameter in the ISP settings.

In "Audit Logs" in Smart Console, we discovered that we can track the switches by entering the ISP's network gateway address in the search bar. This will show us which default gateway was assigned to the FW and when.

But as far as I understand, this option was available even before the "LOG" parameter was set in the ISP settings, but we couldn't find where the logs are stored that we can view after setting this parameter.

0 Kudos
the_rock
MVP Platinum
MVP Platinum

Did you open TAC case for it yet?

Best,
Andy
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events