CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA or CCSE One-Week Certification Training Courses with CPUG in Beautiful San Francisco!
    R70 CCSA Courses Starting (2010) 6/7, 7/12, 8/9, 10/11, 11/8, 12/6.  R70 CCSE Courses Starting (2010) 8/16.
2. CPUG CON 2010 EUROPE, the User Conference in Switzerland, September 20th-22nd, 2010!
3. Join Our CPUG Groups On LinkedIn and Facebook.  See Our Channel on YouTube.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartView Tracker/Logging And Alerting
Register Projects FAQ Members List Social Groups Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 2009-10-29
Junior Member
 
Join Date: 2006-08-09
Posts: 8
Rep Power: 0
lnx32 has an average reputation (10+)
Default Firewalls Not Logging to Remote Server

I am running Checkpoint R62 on 2 Nokia IP390s and Smartcenter on a Windows server. My Appliances started logging locally a few weeks ago and stopped sending the log files to the remote Smartcenter Server. When I noticed the current logs weren't showing up in Tracker I checked the appliances and found that when I did a df -k the /var directory was over 108% on both appliances. I checked the $FWDIR/logs folder and all the logs were being logged here.
What can I do to get the files to stop logging locally and start logging back to the SmartCenter server? I've tried clearing the $FWDIR/logs folder and rebooting both the appliances and the SmartCenter server but they are still logging to the appliances causing the /var directory to to fill up every 3 days or so. What can I do to correct this and get them back on track?
Reply With Quote
  #2 (permalink)  
Old 2009-10-30
Senior Member
 
Join Date: 2009-06-10
Location: NE Ohio
Posts: 1,056
Rep Power: 3
belvdr has an average reputation (10+)
Default Re: Firewalls Not Logging to Remote Server

Is SIC working? Test that first.

Then under Logs and Masters -> Log Servers for each node, uncheck the option "Save logs locally, on this machine". Note, if this is a cluster, the local option is not there.

Also ensure the SCS is under the "Always send logs to" box. If it is not, add your SCS in there and check both Logs and Alerts. Push policy.
Reply With Quote
  #3 (permalink)  
Old 2009-10-30
Junior Member
 
Join Date: 2006-08-09
Posts: 8
Rep Power: 0
lnx32 has an average reputation (10+)
Default Re: Firewalls Not Logging to Remote Server

Yes, SIC is working to both appliances from the SCS. I checked the logging to SCS and these settings are correct! I can figure it out. I was toying with the Idea of just resetting the state tables on both firewalls but that would impact my production traffic.
Reply With Quote
  #4 (permalink)  
Old 2009-10-30
Senior Member
 
Join Date: 2009-06-10
Location: NE Ohio
Posts: 1,056
Rep Power: 3
belvdr has an average reputation (10+)
Default Re: Firewalls Not Logging to Remote Server

So you can push policy, but can you fetch it? Go to one of the boxes and do:

Code:
fw fetch <ip of SCS>
It really sounds as though SIC is initialized only one way, so the SCS can send to the gateway but not vice versa. By running the above command, it will verify it for sure, and it outputs errors too, if there are any.
Reply With Quote
  #5 (permalink)  
Old 2009-10-30
Junior Member
 
Join Date: 2006-08-09
Posts: 8
Rep Power: 0
lnx32 has an average reputation (10+)
Default Re: Firewalls Not Logging to Remote Server

This is what the output looks like on both Appliances........

cp1[admin]# fw fetch 172.29.5.240

Fetching Security Policy From: 172.29.5.240

Local Policy is Up-To-Date.
Reinstalling Local Policy.

Installing Security Policy Standard_1a on all.all@cp1
Oct 30 12:05:53 cp1 [LOG_CRIT] kernel: FW-1: Log buffer is full
Oct 30 12:05:53 cp1 [LOG_CRIT] kernel: fwdynlog_commit: failed translating alert param. i=
121, alert = 1 - setting alert = "log"
Oct 30 12:05:53 cp1 [LOG_CRIT] kernel: fwdynlog_commit: failed translating alert param. i=
122, alert = 1 - setting alert = "log"
Oct 30 12:05:53 cp1 [LOG_CRIT] kernel: FW-1: lost 9459 log/trap messages
Successfully compiled file types magic file.

Oct 30 12:06:04 cp1 [LOG_CRIT] kernel: FW-1: Log buffer is full
Oct 30 12:06:04 cp1 [LOG_CRIT] kernel: FW-1: lost 21 log/trap messages
Oct 30 12:06:04 cp1 [LOG_CRIT] kernel: FW-1: Log buffer is full
Oct 30 12:06:04 cp1 [LOG_CRIT] kernel: FW-1: lost 16 log/trap messages
Oct 30 12:06:04 cp1 [LOG_CRIT] kernel: FW-1: Log buffer is full
Fetching Security Policy Succeeded

cp1[admin]# Oct 30 12:06:21 cp1 [LOG_CRIT] kernel: FW-1: lost 2075 log/trap me
ssages

cp1[admin]#
__________________________________________________ _______________
cp2[admin]# fw fetch 172.29.5.240

Fetching Security Policy From: 172.29.5.240

Local Policy is Up-To-Date.
Reinstalling Local Policy.

Installing Security Policy Standard_1a on all.all@cp2
Oct 30 12:12:50 cp2 [LOG_CRIT] kernel: FW-1: Log buffer is full
Oct 30 12:12:50 cp2 [LOG_CRIT] kernel: FW-1: lost 8926 log/trap messages
Oct 30 12:12:50 cp2 [LOG_CRIT] kernel: FW-1: Log buffer is full
Oct 30 12:12:50 cp2 [LOG_CRIT] kernel: fwdynlog_commit: failed translating alert param. i=
121, alert = 1 - setting alert = "log"
Oct 30 12:12:50 cp2 [LOG_CRIT] kernel: fwdynlog_commit: failed translating alert param. i=
122, alert = 1 - setting alert = "log"
Oct 30 12:12:50 cp2 [LOG_CRIT] kernel: FW-1: lost 12 log/trap messages
Oct 30 12:12:50 cp2 [LOG_CRIT] kernel: FW-1: Log buffer is full
Oct 30 12:12:50 cp2 [LOG_CRIT] kernel: FW-1: lost 64 log/trap messages
Successfully compiled file types magic file.
Oct 30 12:13:01 cp2 [LOG_CRIT] kernel: FW-1: Log buffer is full
Oct 30 12:13:02 cp2 [LOG_CRIT] kernel: FW-1: lost 52 log/trap messages
Oct 30 12:13:02 cp2 [LOG_CRIT] kernel: FW-1: Log buffer is full
Oct 30 12:13:02 cp2 [LOG_CRIT] kernel: FW-1: lost 5 log/trap messages
Oct 30 12:13:02 cp2 [LOG_CRIT] kernel: FW-1: Log buffer is full
Oct 30 12:13:02 cp2 [LOG_CRIT] kernel: FW-1: lost 20 log/trap messages
Oct 30 12:13:02 cp2 [LOG_CRIT] kernel: FW-1: Log buffer is full
Oct 30 12:13:03 cp2 [LOG_CRIT] kernel: FW-1: lost 60 log/trap messages
Oct 30 12:13:03 cp2 [LOG_CRIT] kernel: FW-1: Log buffer is full
Oct 30 12:13:03 cp2 [LOG_CRIT] kernel: FW-1: lost 4 log/trap messages
Oct 30 12:13:03 cp2 [LOG_CRIT] kernel: FW-1: Log buffer is full
Oct 30 12:13:03 cp2 [LOG_CRIT] kernel: FW-1: lost 26 log/trap messages
Oct 30 12:13:03 cp2 [LOG_CRIT] kernel: FW-1: Log buffer is full

Fetching Security Policy Succeeded

cp2[admin]#
Reply With Quote
  #6 (permalink)  
Old 2009-10-30
Senior Member
 
Join Date: 2008-07-31
Location: Netherlands, Europe
Posts: 697
Rep Power: 2
msjouw has an average reputation (10+)
Default Re: Firewalls Not Logging to Remote Server

try the following: on the Gateway Object in the dashboard set the Master and logserver to use local defenition in the Masters file.
On the gateway itself edit $FWDIR/conf/masters and make sure it looks like this (it is from memory so pardon me missing the right words/syntax):
[Policy]
172.29.5.240
[Log]
172.29.5.240
[Alert]
172.29.5.240

And push the policy
__________________
Regards, Maarten.
P1 R65.4 IPSO SPLAT IOS

Last edited by msjouw; 2009-11-02 at 04:01.
Reply With Quote
  #7 (permalink)  
Old 2009-11-01
Junior Member
 
Join Date: 2009-09-29
Location: Israel
Posts: 22
Rep Power: 0
doron.linder has an average reputation (10+)
Default Re: Firewalls Not Logging to Remote Server

Hi lnx32,

I'd suggest you fire up the Tracker on your log server (172.29.5.240) and filter the logs to check that you aren't getting any logs from the two Nokia machines. According to the "kernel: FW-1: Log buffer is full" message my guess is that there is too much traffic going on and although some of it reach the log server, the gateway isn't handling it fast enough and start to log locally so that no log will be lost. Have you tried running "fw debug fwd on TDERROR_ALL_ALL=5" and checking fwd.elg? It might support what I wrote, or at least give you the reason for the disconnection from the log server (if there is a disconnection causing the local logging).

Doron Linder
Logging Matters - Check Point Logging Related Services
Reply With Quote
  #8 (permalink)  
Old 2009-11-01
Junior Member
 
Join Date: 2009-09-29
Location: Israel
Posts: 22
Rep Power: 0
doron.linder has an average reputation (10+)
Default Re: Firewalls Not Logging to Remote Server

And in addition to what I wrote below, first try and make some space available. Move the logs to the log server manually by using the Tracker's Tools -> Remote Files Management -> Fetch files option. It might be that the logging doesn't work since you're out of disk space.

Doron Linder
Logging Matters - Check Point Logging Related Services
Reply With Quote
  #9 (permalink)  
Old 2010-01-07
Junior Member
 
Join Date: 2009-06-30
Posts: 6
Rep Power: 0
krugger has an average reputation (10+)
Default Re: Firewalls Not Logging to Remote Server

Have a similar problem. My R70 ran out of disk space and after I cleaned some of the files the logging is still done locally at the firewalls and not at the SmartCenter server.

SIC is also ok, and have pushed the config again but still it is not resuming logging to the SmartCenter.

fw fetch does not give any errors. The SmartCenter server is set as the logging server. Is there a way to define the logging server through the command line? I am starting to think about a late night reboot of the firewall nodes to try and get the logging back to the SmartCenter server.

It is an active active cluster of R70 firewalls.
Reply With Quote
  #10 (permalink)  
Old 2010-01-07
Senior Member
 
Join Date: 2008-11-22
Location: Atlanta, GA
Posts: 469
Rep Power: 2
boldin has an average reputation (10+)
Default Re: Firewalls Not Logging to Remote Server

This happened with our R65 boxes from time to time and a reboot usually fixes the problem. I think on some occasions a cprestart would work, but not every time if my memory serves me correctly.
__________________
- boldin
CCSA/CCSE NGX R65
Source Fire Certified Professional
Security+
QualysGuard Certified Specialist
A+
Reply With Quote
  #11 (permalink)  
Old 2010-01-07
Junior Member
 
Join Date: 2009-06-30
Posts: 6
Rep Power: 0
krugger has an average reputation (10+)
Default Re: Firewalls Not Logging to Remote Server

So this is some sort of bug that affects multiple FW-1 versions?

Surely there must be a solution I haven't found in the Knowledge Base.
Reply With Quote
  #12 (permalink)  
Old 2010-04-08
Junior Member
 
Join Date: 2006-07-07
Posts: 21
Rep Power: 0
BillM has an average reputation (10+)
Default Re: Firewalls Not Logging to Remote Server

I too am having this problem.

We upgraded our SCS from R61 to R70. It stopped receiving logs from the R61 gateways immediately. The next day, as planned, we upgraded the gateways to R65 and applied the latest HFA. R65 is as high as we could go on our appliance.

SIC is working. I can push or fetch. I have edited the $FWDIR/conf/masters with the IP address of my SCS. I set the object to use local.

Still nothing showing up in tracker.

Bill M
Reply With Quote
  #13 (permalink)  
Old 2010-04-08
Senior Member
 
Join Date: 2009-04-30
Location: Colorado, USA
Posts: 397
Rep Power: 2
ShadowPeak.com has an average reputation (10+)
Default Re: Firewalls Not Logging to Remote Server

Quote:
Originally Posted by BillM View Post
I too am having this problem.

We upgraded our SCS from R61 to R70. It stopped receiving logs from the R61 gateways immediately. The next day, as planned, we upgraded the gateways to R65 and applied the latest HFA. R65 is as high as we could go on our appliance.

SIC is working. I can push or fetch. I have edited the $FWDIR/conf/masters with the IP address of my SCS. I set the object to use local.

Still nothing showing up in tracker.

Bill M
Seen this problem with R70 vanilla numerous times where the SmartCenter refuses to accept logs from older gateways but SIC works fine both ways. Try doing a Policy->Install Database. If that doesn't work you'll have to upgrade your SmartCenter Server to R70.1 or later which will fix the problem.
Reply With Quote
  #14 (permalink)  
Old 2010-04-09
Senior Member
 
Join Date: 2007-06-04
Posts: 1,560
Rep Power: 5
mcnallym has an average reputation (10+)
Default Re: Firewalls Not Logging to Remote Server

After performing an R65 to R70.20 migration on a P-1 CMA we have had an issue where the logging part of the CMA was not receiving the logs even though we could see the logs appearing on the NIC of the MDS.

Was that the CMA was showing the logging as started but did not stop and start correctly.

Had to do the kill -9 to stop the process, after which starting up again we got the logs.

Might be worth performing a cpstop on the Management Server and verifying that all of the services have stopped relating to check point.

If after a cpstop the check point services are still running then manually stop them, then restart the services afterwards.
Reply With Quote
  #15 (permalink)  
Old 2010-04-09
Junior Member
 
Join Date: 2006-07-07
Posts: 21
Rep Power: 0
BillM has an average reputation (10+)
Default Re: Firewalls Not Logging to Remote Server

This worked for me:

1.) Exit SmartDashboard

2.) Run cpstop

3.) Run the following commands:

rm $FWDIR/conf/asm.C*
rm $FWDIR/conf/profiles.C*
rm $FWDIR/conf/ips_tables_sqlite*
rm $FWDIR/conf/CPMILinksMgr.db*

4.) Replace the first three files you deleted with the ones I am attaching (zip file) <-- from our partners at Cadre.

5.) Run cpstart

6.) Log into SmartDashboard. If there are any error messages please take screen shots. If no errors, attempt to install database (Policy -> Install Database) on DRACO.

I am logging again.

Bill M
Reply With Quote
  #16 (permalink)  
Old 2010-04-20
Junior Member
 
Join Date: 2010-04-20
Posts: 7
Rep Power: 0
regmartin has an average reputation (10+)
Default Re: Firewalls Not Logging to Remote Server

For R70 environments, take a look at this post for a possible solution Logging not working -- need help :(
Reply With Quote
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 23:24.


Powered by vBulletin® Version 3.8.5
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.5.1