- Products
- Learn
- Local User Groups
- Partners
-
More
Celebrate the New Year
With CheckMates!
Value of Security
Vendor Self-Awareness
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
Mobile Security
Buyer's Guide Out Now
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Hi,
R80.30 environment. SG cluster is not sending logs to SMS.
Steps that I have done in troubleshooting:
So are there anymore suggestions in troubleshooting this issue? Could it be that the last step (that I didn't do), the active firewall log file fw.log might be corrupted on the SG?
Hi @ED
1) Check the $FWDIR/conf/masters file on the gateway and resolve the IP of the object under log.
2) Start "tcpdump -i ethX port 257" on the gateway and check the traffic to the log server
3) On the Management Server run the following cli command "netstat -an | grep 257" and check that the port 257 is open.
4) Check the firewall ruels "sourece gateway to mangement server port 257"
5) Check NAT rules (no Nat between gateway and management).
6) Check the following on the gateway "cpstat fw -f log_connection"
7) Start "fw ctl zdebug drop | grep 257"on the gateway
8.) Start "tcpdump -i ethX port 257" on the managemet and check the traffic to the log server
9) If you see traffic on the management server and no log entrys -> restart the management server "cpstart/cpstop"
10) Set in the GAIA GUI the "management Interface" on the correct interface.
11) Check the disk space on the management server under "var/log/"
12) Check the process fwd with "top" or "ps -aux |grep fwd"
13) Check the fwd process with "cpwd_admin list"
14) Install the latest JHF.
If none of this helps, open a ticket at Check Point.
@PhoneBoy I tried telnet on port 257 from SG to the SMS and it was successful. Could also see that on the SMS with the netstat command.
I also tried the laste step that I wrote above, fixing the potentially corrupted fw.log file on SG but it didn't help.
I would check FWD logs / debug it, more info here how to do it
Check the log connection state & IP of your Mgmt/LS, that your GW is trying to send logs to by running on the GW (attach here):
cpstat fw -f log_connection
Do you have any NATs on your env?
Hi @ED
1) Check the $FWDIR/conf/masters file on the gateway and resolve the IP of the object under log.
2) Start "tcpdump -i ethX port 257" on the gateway and check the traffic to the log server
3) On the Management Server run the following cli command "netstat -an | grep 257" and check that the port 257 is open.
4) Check the firewall ruels "sourece gateway to mangement server port 257"
5) Check NAT rules (no Nat between gateway and management).
6) Check the following on the gateway "cpstat fw -f log_connection"
7) Start "fw ctl zdebug drop | grep 257"on the gateway
8.) Start "tcpdump -i ethX port 257" on the managemet and check the traffic to the log server
9) If you see traffic on the management server and no log entrys -> restart the management server "cpstart/cpstop"
10) Set in the GAIA GUI the "management Interface" on the correct interface.
11) Check the disk space on the management server under "var/log/"
12) Check the process fwd with "top" or "ps -aux |grep fwd"
13) Check the fwd process with "cpwd_admin list"
14) Install the latest JHF.
If none of this helps, open a ticket at Check Point.
Hi Ed,
just curious, what was your issue & what exactly in Heiko's suggested steps solved it?
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY