CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartView Tracker/Logging And Alerting
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-11-06
Youngy Youngy is offline
Member
 
Join Date: 2005-09-20
Posts: 83
Rep Power: 3
Youngy has an average reputation (10+)
Default one enforcement point not logging

Hi all,

Just wondering if anyone else has had an issue like this. Basically my CP management server receives logs from a number of FW enforcement points. All appears to be working correctly, but for one enforcement point not showing any logs or traffic in the tracker.

The enforcement point is set to send logs to the menegement server, it can oing the management server and so on. The enforcement point is a Nokia ISPO so I was wondering is there a way to tell if this device is even generating logs.

Thanks
Reply With Quote
  #2 (permalink)  
Old 2005-11-07
Lackie Lackie is offline
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: one enforcement point not logging

Can you ping the Management station from the firewall that isn't logging? You may need rules to allow this.

Can you ping the other way around? Again, may need rules.

Can you push policies to the firewall? Can you fetch policies?

You can do a tcpdump on the Nokia to see if it's trying to send the logs to the management station... i.e. tcpdump -i eth1 port 257. I used eth1 for my interface name, your's may be different. Use the interface that is pointing to the management station.

Where is the management station in location related to the firewall? Is it directly connected, is it behind another firewall? Is it accessable to the firewall?

Did this firewall ever log to the management station?

Is the log file on the Nokia growing? You can check this by changing to $FWDIR/log and running an ls -al, checking the size of the fw.log file and running the ls -al command again and rechecking the size.

Last edited by Lackie; 2005-11-07 at 11:27.
Reply With Quote
  #3 (permalink)  
Old 2005-11-07
Youngy Youngy is offline
Member
 
Join Date: 2005-09-20
Posts: 83
Rep Power: 3
Youngy has an average reputation (10+)
Default Re: one enforcement point not logging

Hi Lackie,

Yes I can ping both ways. I can also push new rules and settings to the firewall from the management server.

I will try the dump once I confirm the physical relationship.

Not sure if it has ever logged as I have not been looking after the checkpoint system very long (I am in the deep end).

The log file is growing but there is no information from this one enforcement point. The log contains entries from other enforcement points.

Thanks
Reply With Quote
  #4 (permalink)  
Old 2005-11-08
Youngy Youngy is offline
Member
 
Join Date: 2005-09-20
Posts: 83
Rep Power: 3
Youngy has an average reputation (10+)
Default Re: one enforcement point not logging

Hi all,

This has been resolved by creating another fw object set up with logging on it and pointing the fw enforcement point to this new object.

The interetsing thing is that under the topology of the other FW management object that was not receiving logs the IP address had been manually added to the topology - but obviously was not working as one would expect.

Thanks all
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 17:26.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0