- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: Checkpoint Log Server Origin
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Checkpoint Log Server Origin
Hi All,
We have a Checkpoint Security Gateway and SMS Server running R81.10. Previously, all gateways sent logs to the SMS . After configuring a dedicated log server, the gateways are now sending logs to this log server. However, some gateways still show the SMS as the log server origin network reachability(Ping to the log server) is okay. What could be causing this issue, and how can we resolve it?
Thanks,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey bro,
How do you have below configured? That could be an issue.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Andy, the same way as your screenshot for all securitygateway.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In my lab, no issues with it. I would need to see for myself to verify the config is right.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
A database install should help also 🙂
Akos
\m/_(>_<)_\m/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Ihenock1011
I would like to comlement my earlier post 🙂
Dig a little bit deeper.
What does this comman say on the LOG server?
- #cpstat ls -f logging
All the clusters are listed, and some of them are "disconnected" state?
- The logging uses TCP 257 -> this prot is open from the clusters to the LOG server?
And check this sk: https://support.checkpoint.com/results/sk/sk40090
Akos
\m/_(>_<)_\m/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I applaud 1st and 2nd response brother 🙂
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@AkosBakos Yes, for those security gateways in the cluster, the status shows disconnected. How can I resolve this issue then?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Ihenock1011
Sorry, I'm in an another timezone 🙂
Because I don't know the exact situation, I suggest you to follow the steps in this sk:
And check this sk: https://support.checkpoint.com/results/sk/sk40090
First, I would start a really basic step: #telnet <LOGserverIP> 257 from the cluster
The LOG server is in the same subnet as the MGMT?
Akos
\m/_(>_<)_\m/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Connectivity seems to be fine. I might need to create a TAC case to further investigate the issue. Thank You Guys for your usual help I will update you their response here.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Maybe before you open the case, just run tcpdumps on given port(s) and it will show you for sure if thats the problem.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Does it give a reason why they are disconnected? That could be why this is happening. Can you send a screenshot please?
Andy
