CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Installing And Upgrading
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-12-05
Member
 
Join Date: 2006-05-08
Posts: 68
Rep Power: 3
mcarey has an average reputation (10+)
Default Move Customer log Module Log File

I would like to place the CLM software on Server A and then map a drive to another directory on Server B, and then point the CLM software to write the logs to the directory on Server B, through a mapped drive.

Has anyone done this?
Reply With Quote
  #2 (permalink)  
Old 2007-12-06
Senior Member
 
Join Date: 2007-06-04
Posts: 1,095
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Move Customer log Module Log File

To redirect log files to another drive or path:

Windows NT/2000
1. Add to registry a new string value of FWLOGDIR under one of the following registry locations:

FireWall-1 4.1:

HKEY_LOCAL_MACHINE\SOFTWARE\CheckPoint\FW1\4.1

FireWall-1 NG and NGX:

HKEY_LOCAL_MACHINE\SOFTWARE\CheckPoint\FW1\5.0
2. Create a new directory (for example C:\MyLogs) and define a String value named FWLOGDIR containing the log path (C:\MyLogs) under HKEY_LOCAL_MACHINE\SOFTWARE\CheckPoint\FW1\5.0

Note: The target path directory must exist prior to modifying the registry. In NGX, you should enter "6.0" in the path mentioned, instead of "5.0".
3. Reboot server.


NOTE: Disable ANTI-VIRUS software.

UNIX

On UNIX machines, symbolically link $FWDIR/log directory to another drive.

Example:

fwstop (cpstop on NG and NGX)
mv $FWDIR/log $FWDIR/log.old
ln -s /path/to/new/logdir $FWDIR/log
fwstart (cpstart on NG and NGX)


WARNING:
DO NOT place log directory on a remote file system. This might result an unpredicted corruptions in active log files (fw.log, fw.adtlog).

Applies To:

• VPN-1 Pro NGX and all previous versions
• Windows OS
• Unix
• Logging
• Redirect log files
• Log Directory

It would seem that Check Point recommend that you do not map a drive to another system and link the log directory to it.

Why do you need to do such a complex method, would it not be easier to either increase the disk space on ServerA or just relocate the CLM to ServerB.
Reply With Quote
  #3 (permalink)  
Old 2007-12-20
Member
 
Join Date: 2006-05-08
Posts: 68
Rep Power: 3
mcarey has an average reputation (10+)
Default Re: Move Customer log Module Log File

You are correct, my Checkpoint SE is recommending to not do this.

This is for one of our customers, and I'm trying to come up with an archive and purging plan for the logs to avoid this configuration.

Thanks
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 01:51.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0