Hello everyone,
I have the following topology (screenshot attached):
A cluster with (2) firewalls and (1) Management Server, both firewalls forward logs to the management server and external log server.
My problem is whenever I published a policy, I lose receiving logs from both firewalls in the SmartConsole, but the external log server keeps receiving all logs as usual.
The way I used to workaround it is to remove the management server from the Log section in the cluster settings, publish the session then put the management server back and publish the policy again. But this workaround is not working anymore for no reason.
Please note that I tried tcpdump on both firewalls and the management server over port 257 but no packets have been captured, and I checked the management server it's listening on port 257.
I tried every possible solution I found on the internet with no result.
Anyone can help, please?
Thanks