CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Crossbeam
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-08-29
Junior Member
 
Join Date: 2006-02-04
Posts: 22
Rep Power: 0
usman_a has an average reputation (10+)
Default Aug 9 08:00:10 firewall kernel: FW-1: Log buffer is full

Can someone advice me on how i can fix teh following error?

Aug 9 08:00:10 firewall kernel: FW-1: lost 592 log/trap messages
Aug 9 08:00:10 firewall kernel: FW-1: Log buffer is full
Aug 9 08:00:10 firewall kernel: FW-1: lost 2011 log/trap messages
Aug 9 08:00:10 firewall kernel: FW-1: Log buffer is full
Aug 9 08:00:10 firewall kernel: FW-1: lost 1324 log/trap messages


i have two crossbeam firewalls with a Sun Sloairs management server.

any advice would be helpful
__________________
I used to think a firewall was a borken router but now i know thats its a hub!
Reply With Quote
  #2 (permalink)  
Old 2007-08-31
Junior Member
 
Join Date: 2007-01-26
Posts: 19
Rep Power: 0
mikem has an average reputation (10+)
Default Re: Aug 9 08:00:10 firewall kernel: FW-1: Log buffer is full

Basic checks is to ensure there are no network connectivity issues from the enforcement points to the MS

One solution is to of course reduce how much you log. For example do you log the drop rule?

Another solution is to allocate additional memory on the enforcement points so they buffer additional logs. You would change the log buffer queue size (if you have the memory available)

Below is how I configured mine. (linux OS) I think I doubled or tripled default.

A workaround is to decrease logging.

Then, as a permanent fix, edit the /etc/system file on enforcement module and add the "set" command as follows:

set fw:fw_log_bufsize=xxxxx

Where xxxx is the desired size in bytes (default = 81920)

Reboot the VPN-1/FireWall-1 Enforcement Point module for the change to take effect.

It is possible to set this value on the fly by running 'fw ctl set int fw_log_bufsize xxxxx' but it won't be persistent across reboots.



For Linux platform, please refer to solution



----------

How to increase the log buffer size on Linux platforms?



Solution

--------

Add the following line in the $FWDIR/boot/modules/fwkern.conf file

(note that the file may not exist by default):



fw_log_bufsize=xxxxx



Where xxxx is the desired size in bytes (default = 81920).

After changing this you have to reboot the module.

mike
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 11:29.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0