CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Management High Availability
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-11-12
Senior Member
 
Join Date: 2007-09-17
Location: Singapore
Posts: 161
Rep Power: 2
chuachongchee has an average reputation (10+)
Default Slow Logging to Sec Mgmt Server

Hi All,

Current Setup:
172.16.12.113/24: Pri Smartcenter
172.16.12.114/24: Sec Smartcenter

Logging setup:
Send to master, Pri, if unreachable, send to sec

A few things i need to clarify:
1) Is the promotion/demotion of the scs "manual"?
In the active(pri) scs, change to standby, then login to the standby(sec) then change to active. Have done a mgmt ha setup during my checkpoint course days, but thats like almost a yr ago, cant remember and havent done any mgmt ha since then.. lol

2) If i unplug the pri scs, the logs take like 15mins to go to the sec scs..
I tried doing a dump on the sec scs and kept seeing logs coming in, but going to the pri ip address.. soo strange... and the thing is that, for the log to "swing" to the sec, it takes 15mins.... then i can see it on the tracker in sec scs... but if i replug in the pri, logs are up almost immediately....

Can anyone help with my queries? Thanks alot in advance..
Reply With Quote
  #2 (permalink)  
Old 2007-11-13
Senior Member
 
Join Date: 2007-09-17
Location: Singapore
Posts: 161
Rep Power: 2
chuachongchee has an average reputation (10+)
Default Re: Slow Logging to Sec Mgmt Server

Hi All,

On Issue #2, i have resloved it already, what happened was that there were 4 firewall clusters managed by the smartcenter, 2 of them had the updated log server config "when unreachable, send logs to sec scs", coz they had some maintenance done on them, apprantly not the other 2, i happened to check on fw stat and founf the policy installed some weeks back.. after i install(reupdated) the policy, everthing works fine and fast... lol
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 08:29.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0