CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA or CCSE One-Week Certification Training Courses with CPUG in Beautiful San Francisco!
    R70 CCSA Courses Starting (2010) 6/7, 7/12, 8/9, 10/11, 11/8, 12/6.  R70 CCSE Courses Starting (2010) 8/16.
2. CPUG CON 2010 EUROPE, the User Conference in Switzerland, September 20th-22nd, 2010!
3. Join Our CPUG Groups On LinkedIn and Facebook.  See Our Channel on YouTube.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartView Tracker/Logging And Alerting
Register Projects FAQ Members List Social Groups Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 2010-01-12
Junior Member
 
Join Date: 2007-08-14
Posts: 10
Rep Power: 0
achillesheel has an average reputation (10+)
Default Firewall log unification scheme error

All,

I have a firewall module NG AI R55 managed by HA SMARTCenter servers (NG AI R55) . Lets assume
SC2 is active
SC1 is standby

On firewall object, log servers are defined in the order SC2, SC1 and "Define Log Servers" radio button is selected. Local logging is turned off.

whereas on /var/opt/CPfw-R55/conf/masters file log servers are defined in the order SC1, SC2 with names.

Firewall is not logging to either of the SC. When I ran "fw log" on module, I get the following error message
Unable to read unification scheme file ' (Default scheme) ' .
fw monitor or tcpdump shows nothing going out on 257.
Telnet to SC on port 257 is successful.
SIC is communicating. I can install policy on firewall
This was working until 2nd January and all of a sudden stopped. I dont have any audit logs as well to see what happened on that day. Im trying to see any syslogs related to this. Also I dont see any manual name resolution entries on /etc/hosts file for the SC names, not sure how firewall resolves the SC names. This is a production firewall hence I wont be able to afford to do any cprestart for now just to see if that resolves.

Firewall details

Module : CP NG AI R55 on Nokia IP box
SC (both) : CP NG AI R55 on Windows machine

Any help is greatly appreciated.
Reply With Quote
  #2 (permalink)  
Old 2010-01-12
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 876
Rep Power: 5
lammbo has an average reputation (10+)
Default Re: Firewall log unification scheme error

R55 in production... Really?!?

Man, you seriously need to upgrade. That product is EOL.

Aside from that, why exactly can't you reboot because it's in production? It's an HA cluster and therefore rebooting one gateway will just make you run on the other one - that's the entire reason to do HA. You should be able to bounce back and forth all day long and most people wouldn't even notice. That's the whole point of state sync.

Just reboot the standby first and then when it comes back online into the cluster, reboot the primary.
__________________
There's no place like 127.0.0.1
Reply With Quote
  #3 (permalink)  
Old 2010-01-13
Junior Member
 
Join Date: 2007-08-14
Posts: 10
Rep Power: 0
achillesheel has an average reputation (10+)
Default Re: Firewall log unification scheme error

Hi Lammbo,

Yes R55 is production, we are pushing for the upgrade sooner. Meanwhile I faced this issue which i have to get it resolved asap.
Firewall is not HA but the SMART Center and I mentioned I cant afford reboot/cprestart unless and otherwise no technical explanation/solution is available. I have to convince the client on that point. Hence requesting if any one of you have come across this error before.
Check Point usercenter says the unified log file isnt generated but no solution is given.
Reply With Quote
  #4 (permalink)  
Old 2010-01-21
Junior Member
 
Join Date: 2009-09-29
Location: Israel
Posts: 22
Rep Power: 0
doron.linder has an average reputation (10+)
Default Re: Firewall log unification scheme error

Hi achillesheel,

In $FWDIR/conf there should be a couple of log unification files definitions. One for Tracker (and fw log command), one for LEA and one for Reporter. The one you seem to be missing is log_unification.C.
I'd try to back it up if it exists and copy this file from another R55 gateway you have. Then restart FWD using cpwd_admin.

Doron Linder
Logging Matters - Check Point Logging Related Services
Reply With Quote
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 23:18.


Powered by vBulletin® Version 3.8.5
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.5.1