CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartView Tracker/Logging And Alerting
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-01-04
Youngy Youngy is offline
Member
 
Join Date: 2005-09-20
Posts: 83
Rep Power: 4
Youngy has an average reputation (10+)
Default Logging ceases after policy install

Hi all,

As you may know I have been having a hell of time getting logging to work consistently on an inherited CP install.

Basically the symptoms are that if you make a policy\object change and push\install the policy the logging from the firewall enforcement stops. The setup is distributed and the management server manages multiple enforcement points.

To get logging to work again I have found that I can do so by:
1. Turn off logging under the properties for the enforcement point object and apply the policy change
2. Turn logging back on under the properties and push the policy again.

Then at that stage you can see logging occurring once again under the tracker.

So far I have applied the latest HFAs to both the enforcement point and management server. The issue remains.

I feel it may be something to do with how the distribution is set up. For example the management machine (windows server) has three bindings on the one NIC. The primary binding and two others obviously.

If the enforcement point can see the primary NIC binding there is no issue, however if the enforcement point sees the management server via one of the other bindings the issue occurs. Now I am suspicious that this is part of the issue.

Has anyone else had any experience like this?

Thanks
Reply With Quote
  #2 (permalink)  
Old 2006-01-04
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,648
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Logging ceases after policy install

Quote:
Originally Posted by Youngy
I feel it may be something to do with how the distribution is set up. For example the management machine (windows server) has three bindings on the one NIC. The primary binding and two others obviously.

If the enforcement point can see the primary NIC binding there is no issue, however if the enforcement point sees the management server via one of the other bindings the issue occurs. Now I am suspicious that this is part of the issue.
Have you tried to add the other interfaces of the SmartCenter to its topology and reset the SIC?

-jlh
Reply With Quote
  #3 (permalink)  
Old 2006-01-11
Youngy Youngy is offline
Member
 
Join Date: 2005-09-20
Posts: 83
Rep Power: 4
Youngy has an average reputation (10+)
Default Re: Logging ceases after policy install

Hi Jim,

Yes the topolgy is complete for all three host objects (two of them I created with the primary IP being that of the NIC binding the FW can see).

I don't believe I have an issue with SIC so how will resetting it play a role in this case?

Cheers
Reply With Quote
  #4 (permalink)  
Old 2006-01-11
mdsenv mdsenv is offline
Junior Member
 
Join Date: 2005-09-27
Posts: 9
Rep Power: 0
mdsenv has an average reputation (10+)
Default Re: Logging ceases after policy install

When the logging stops, does the $FWDIR\log\fw.log file on the firewall grow in size?

When logging stops, have you tried running a tcp dump on the firewall?
Reply With Quote
  #5 (permalink)  
Old 2006-01-13
Claer Claer is offline
Junior Member
 
Join Date: 2005-08-19
Posts: 14
Rep Power: 0
Claer has an average reputation (10+)
Default Re: Logging ceases after policy install

I encoutered a similar problem.
The management stopped to log modules and a message indicating so appears in the smart view tracker. The solution given by the support was to convert Smartcenter to host (it was defined as a gw)
The support didn't know why this problem occurs time to time.
Reply With Quote
  #6 (permalink)  
Old 2006-01-16
Youngy Youngy is offline
Member
 
Join Date: 2005-09-20
Posts: 83
Rep Power: 4
Youngy has an average reputation (10+)
Default Re: Logging ceases after policy install

Hi,

Yeah the smart center is already set as a host. I'll have to check out mdsenv's suggestion at somepoint this week.

Thanks Guys
Reply With Quote
  #7 (permalink)  
Old 2006-01-21
Sergej Sergej is offline
Senior Member
 
Join Date: 2005-11-21
Location: Europe, Lithuania
Posts: 291
Rep Power: 3
Sergej has an average reputation (10+)
Default Re: Logging ceases after policy install

Knowledge base article sk30530 describes the same situation. They advise basically the same you have already done: "Remove all interfaces on the Topology page of the host object representing the SmartCenter Server, and install the Security Policy"

Last edited by Sergej; 2006-01-21 at 11:45.
Reply With Quote
  #8 (permalink)  
Old 2006-01-22
Prabhu84818 Prabhu84818 is offline
Junior Member
 
Join Date: 2006-01-18
Posts: 3
Rep Power: 0
Prabhu84818 has an average reputation (10+)
Default Re: Logging ceases after policy install

hai
I am having the similar problem. I Removed all interfaces on the Topology page of the host object representing the SmartCenter Server, and once again i installed the Security Policy. still i cant get the log file while viewing Smartview tracker. this contains log files only of type "Control". please let me know the solution for this.

Thanks & Regards
Prabhu S

Last edited by Prabhu84818; 2006-01-22 at 22:43.
Reply With Quote
  #9 (permalink)  
Old 2006-01-31
Youngy Youngy is offline
Member
 
Join Date: 2005-09-20
Posts: 83
Rep Power: 4
Youngy has an average reputation (10+)
Default Re: Logging ceases after policy install

Hi Prabhu84818,

I think your issue might be slightly different, it sounds like you are not getting any log information on your smart center server. My case is all logging is working - but stops after you do an policy change\push. And I fix this as per my first post.

You may need to look into connectivity between your smart center server and fw on port 257 (port used for cp logging). see if the smart center server is listening on that port etc etc. Check masters file and that sort of thing.

Cheers
Reply With Quote
  #10 (permalink)  
Old 2006-02-05
Youngy Youngy is offline
Member
 
Join Date: 2005-09-20
Posts: 83
Rep Power: 4
Youngy has an average reputation (10+)
Default Re: Logging ceases after policy install

Hello all,

Just letting you all know that this issue has been resolved. I basically resolved this case myself so the resolution will not be as precise as you will no doubt expect.

Basically I had a case open with CP since the 20/11/05 and up loaded tonnes of cpinfo outputs the results of this test and that etc and we did not appear to be making much progress.

So I built a brand new 2003 server machine. Did an upgrade/import onto this new box and tah dah. Logging does not cease when you push a policy. Somehere in there is the fix..................:)

Cheers
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 11:24.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0