CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point SecurePlatform (SPLAT)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-08-11
Senior Member
 
Join Date: 2006-09-26
Posts: 804
Rep Power: 3
cciesec2006 has an average reputation (10+)
Default gateways R55 stop sending log to NGx R65 CLM and stand-alone log server

I have this issue and it has been driving me crazy for the past week or so.

I have a environment with a CMA NG with AI R55 with HFA_17 managing
about 20+ Secureplatform NG with AI R55 gateways with HFA_17. I also have
an Customer Log Module (CLM) residing inside a Multi-Log Module (MLM). In
addition to that, I also have stand-alone log server. Gateways send
log to both the CLM and the stand-alone log server. Everything is working
fine.

Two weeks ago, I migrated the CMA from NG with AI R55 to NGx R65 with
HFA_02 and hf_249. I also have a new Customer Log Module in NGx R65 as well.
On top of that, I also added a new stand-alone log server NGx R65.
Everything is Secureplatform. In other words, I have a new CLM, an old
R55 stand-alone log server and a new NGx R65 stand-alone log server.
In other words, my gateways are sending log to three different places:
new CLM, new stand-alone log server and old R55 stand-alone log server.
The gateways are still on NG with AI R55 with HFA_17.

For the past week, some of the gateways just stop sending logs to both the
new CLM and new NGx R65 stand-alone log server. The gateways NEVER stops
sending logs to the old R55 stand-alone server. The only way for me to fix
this is to reboot the gateways. After that, the gateway starts sending
log to the NGx CLM and stand-alone NGx R65 log server. A few days later,
it stops sending log again.

Anyone know what could be the issue? Thanks.
Reply With Quote
  #2 (permalink)  
Old 2008-08-29
Member
 
Join Date: 2007-02-27
Posts: 80
Rep Power: 2
th0i3 has an average reputation (10+)
Default Re: gateways R55 stop sending log to NGx R65 CLM and stand-alone log server

Fortunately, I came across this issue before. This is a bug which is apparently fixed in R65 HFA02 (enforcement module). You need to turn on kernel debug for logging which you'll have to research. Look for this error.

sendLogs: Fatal error, Conn ID=64, La st Seq=2147483647, New Seq=-1492181850, Bad new Seq

It may be a different problem.
Reply With Quote
  #3 (permalink)  
Old 2008-08-31
Senior Member
 
Join Date: 2008-07-31
Location: Netherlands, Europe
Posts: 252
Rep Power: 1
msjouw has an average reputation (10+)
Default Re: gateways R55 stop sending log to NGx R65 CLM and stand-alone log server

We have similar problems with a R62 CMA and some R62 and R55 AI Gateways however this happens very rarely, something like once every 3 months.
Reply With Quote
  #4 (permalink)  
Old 2008-08-31
Member
 
Join Date: 2007-02-27
Posts: 80
Rep Power: 2
th0i3 has an average reputation (10+)
Default Re: gateways R55 stop sending log to NGx R65 CLM and stand-alone log server

Yup, that is the exact symptom my customer is having.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 06:59.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0