CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartView Tracker/Logging And Alerting
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-09-04
herrmadbeef herrmadbeef is offline
Junior Member
 
Join Date: 2005-09-26
Posts: 19
Rep Power: 0
herrmadbeef has an average reputation (10+)
Default not logging

Hi we just update a Smartcenter server and its not logging

we update form r55 to r60
and the SCS apply the security policy with no problem

but the smart view tracker do not log any event

does any1 has a clue

thanks
Reply With Quote
  #2 (permalink)  
Old 2006-09-05
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 786
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: not logging

What platforms are you using?

Are you logging back to your smartcenter server, or another platform?

What is configured on your firewall objects for logging?

Do you see any tcp/257 traffic leaving the firewalls going to the management server?
Reply With Quote
  #3 (permalink)  
Old 2006-09-05
herrmadbeef herrmadbeef is offline
Junior Member
 
Join Date: 2005-09-26
Posts: 19
Rep Power: 0
herrmadbeef has an average reputation (10+)
Default Re: not logging

the smart center server is in Windows2003 (updated to r60)
and the Enforment module is a Nokia ipso 3.9 r60 (updated)

the master log server in the enforcment is the Smart center server

and i dont see any packet going on in the tracker
Reply With Quote
  #4 (permalink)  
Old 2006-09-05
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 786
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: not logging

Well, yeah, you're not going to see anything in Tracker if it's not logging...

Try running tcpdump on the IPSO box for a while, looking for tcp/257 going from the firewall to the management server.

Also take a look at the contents of $FWDIR/log. fw.log should be growing if it's now logging locally.

I have sometimes seen logging get a bit messed up and require a restart on the module - normally they just detect that the log server is back up and deal with it. Occasionally they don't seem to properly deal with it though. If it's practical, you might like to try a stop/start on the module. You shouldn't _have_ to do that, but sometimes it seems to be required.

Given that you've already pushed policy, it's reasonable to assume that it's not a SIC-related issue - nor should it be. You could try running fw log at the command line on the module, to get it to convert the logs into human-readable format on the command line, so you can doublecheck there's nothing odd in there, like changed anti-spoofing. Again, since you've been able to push policy, that shouldn't be an issue.

Also, from the module, can you telnet to the management server on port 257, just to doublecheck that everything is cool at a routing level?
Reply With Quote
  #5 (permalink)  
Old 2006-09-06
aqw789 aqw789 is offline
Junior Member
 
Join Date: 2006-08-31
Posts: 10
Rep Power: 0
aqw789 has an average reputation (10+)
Default Re: not logging

A few months ago we also experienced the same problems. The module didn't log to the management station anymore.
We had to stop/start the firewall daemons of the enforcement module to get the logs back to the management station.
Reply With Quote
  #6 (permalink)  
Old 2006-09-06
herrmadbeef herrmadbeef is offline
Junior Member
 
Join Date: 2005-09-26
Posts: 19
Rep Power: 0
herrmadbeef has an average reputation (10+)
Default Re: not logging

ok ill try to do that

but its wierd 'cause you have to update first the smartcenter so is back online
and the u upgrade the enforcment so should be online at all times

ill try
thanks
Reply With Quote
  #7 (permalink)  
Old 2006-09-08
Bikky Bikky is offline
Junior Member
 
Join Date: 2005-10-18
Location: Newcastle - UK
Posts: 14
Rep Power: 0
Bikky has an average reputation (10+)
Default Re: not logging

ahh, gonna try that too, and i HAVEN'T upgraded, our security team just got onto me saying the last weeks worth of logs are empty, all i've got is log switch message and CA messages. (ie between 1 and 3 per day)

nice of them to get onto me when it first started happeneing.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 01:10.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0