CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartView Tracker/Logging And Alerting
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-02-07
mjoc27x mjoc27x is offline
Junior Member
 
Join Date: 2006-02-07
Posts: 6
Rep Power: 0
mjoc27x has an average reputation (10+)
Default SmartView Tracker not receiving logs

I have a problem between an enforcement module and a smartcenter server. The Enforcement Module appears to be connecting to the SmartCenter and sending the logs, but they're not showing up in Smartview Tracker or being recorded in the log directory on the SmartCenter.

There is a Cisco PIX between the two servers (sorry, so unpatriotic) on which I can see a connection on port 257/tcp (syn, syn-ack, some data and fin packets). I can see the session in netstat on both servers. So it appears to me that the log should be working, but it isn't. All I've got in the log on the smartcenter are messages from the smartcenter itself.

The log on the Enforcement module is working -- i can see it using 'fw log', but I really need to see it in the Smartcenter.

I can retrieve log files from the CLI (fw fetchlogs), but not from the SmartTracker GUI -- it aborts immediately.

I'm not seeing any traffic being blocked on the PIX.

Any ideas anyone? Any help greatly appreciated.

Mike.
Reply With Quote
  #2 (permalink)  
Old 2006-02-07
kva.kva kva.kva is offline
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: SmartView Tracker not receiving logs

Does fw.log on SmartCenter increase?

Try to "Install database" on SmartCenter object from SmartDashboard client.
Reply With Quote
  #3 (permalink)  
Old 2006-02-07
Youngy Youngy is offline
Member
 
Join Date: 2005-09-20
Posts: 83
Rep Power: 3
Youngy has an average reputation (10+)
Default Re: SmartView Tracker not receiving logs

I have a case open with CP at the moment in relation to this issue. But you appear to be past the issue I have as we don't seem to be able to get any thing going over 257.

The masters file is set correctly I can ping the object Ip that logging is addressed to in the config by name and IP from the enforcement point still know joy.

I'll hopefully pick up some tips from this thread!
Reply With Quote
  #4 (permalink)  
Old 2006-02-09
ddarby1 ddarby1 is offline
Member
 
Join Date: 2006-01-09
Posts: 72
Rep Power: 3
ddarby1 has an average reputation (10+)
Default Re: SmartView Tracker not receiving logs

Hi,

Just a thought, but I'd start by ruling out the PIX completely if possible. I don't know the configuration on your PIX, but its likely to be NATing the connection between the enforcement module and the management/log server and I was wondering if that might be causing the problem?

I'd try using the 'nat 0' command on the PIX for the required traffic or temporarily replace it with a router to confirm or eliminate it as the cause of the problem.
Reply With Quote
  #5 (permalink)  
Old 2006-02-09
ddarby1 ddarby1 is offline
Member
 
Join Date: 2006-01-09
Posts: 72
Rep Power: 3
ddarby1 has an average reputation (10+)
Default Re: SmartView Tracker not receiving logs

Hi again,

I had a quick go on what I presume is a similar configuration: it worked using the 'nat 0' command on the PIX for both the Management/Log Server and the Enforcement Module (causing the PIX to perform like a router).

Other than that, an access-list was required to let tcp/257 through from the enforcement module to the Smart Center (the E/Module was on the PIX's outside interface and the Smart Center server on the inside).

The final thing would be to make sure routing is setup properly on all 3 parties, but it sounds like you had that configured properly anyway.

Does this reflect your config at all?

S/W used: PIX OS 6.3(5), Check Point NGX
Reply With Quote
  #6 (permalink)  
Old 2006-02-09
mjoc27x mjoc27x is offline
Junior Member
 
Join Date: 2006-02-07
Posts: 6
Rep Power: 0
mjoc27x has an average reputation (10+)
Default Re: SmartView Tracker not receiving logs

Quote:
Just a thought, but I'd start by ruling out the PIX completely if possible. I don't know the configuration on your PIX, but its likely to be NATing the connection between the enforcement module and the management/log server and I was wondering if that might be causing the problem?

I'd try using the 'nat 0' command on the PIX for the required traffic or temporarily replace it with a router to confirm or eliminate it as the cause of the problem.
The traffic is definately passing through the PIX, I can see it with a 'debug packet'. The nat 0 has been in place and working for a while.
and unfortunately it's too 'live' to replace the PIX with a router.

Quote:
Does fw.log on SmartCenter increase?
Yes, but only by a tiny amount due to the entries generated by the SmartCentre itself.

Quote:
Try to "Install database" on SmartCenter object from SmartDashboard client.
Just tried that - no better, I'm afraid.

Thank you for you help so far.
Mike.
Reply With Quote
  #7 (permalink)  
Old 2006-02-09
mjoc27x mjoc27x is offline
Junior Member
 
Join Date: 2006-02-07
Posts: 6
Rep Power: 0
mjoc27x has an average reputation (10+)
Default Re: SmartView Tracker not receiving logs

Quote:
Originally Posted by ddarby1
Does this reflect your config at all?

S/W used: PIX OS 6.3(5), Check Point NGX
It's PIX 6.3(3) and CP NG with AI R55W.

Cheers,
Mike.
Reply With Quote
  #8 (permalink)  
Old 2006-02-09
mjoc27x mjoc27x is offline
Junior Member
 
Join Date: 2006-02-07
Posts: 6
Rep Power: 0
mjoc27x has an average reputation (10+)
Default Re: SmartView Tracker not receiving logs - Fixed!

Fixed, but not entirely happy with the solution:

At some point, I had un-ticked the Checkpoint option in the list of components for the network card on the SmartCentre server. When I ticked this it killed my remote access (MS Terminal Services) but started logging. I then configured the SmartCentre to be a Firewall as well as a SmartCenter and Log server, defined a couple of rules for remote access to it and it all worked -- logging and remote admin access.

Now the question is - Why? Can't you have a SC or log server that isn't also a firewall?

Answers on a postcard to the usual address please.

Thank you once again for all your time, effort and suggestions.

Mike.
Reply With Quote
  #9 (permalink)  
Old 2006-02-12
Youngy Youngy is offline
Member
 
Join Date: 2005-09-20
Posts: 83
Rep Power: 3
Youngy has an average reputation (10+)
Default Re: SmartView Tracker not receiving logs

Hi,

You should not have to have the smartcentre server set as a firewall object as well for loggin to occur. But then again this is checkpoint and nothing is really that surprising...........:)
Reply With Quote
  #10 (permalink)  
Old 2006-10-04
kranti kranti is offline
Junior Member
 
Join Date: 2006-09-11
Posts: 8
Rep Power: 0
kranti has an average reputation (10+)
Send a message via Yahoo to kranti
Default Re: SmartView Tracker not receiving logs

Hi Young,

I am facing the same problem which you have faced.
My problem is

my CP management server receives logs from a all FW enforcement points. All appears to be working correctly, but for one enforcement point not showing any logs or traffic in the tracker.

The enforcement point is set to send logs to the menegement server, it can oing the management server and so on. The enforcement point is a Nokia ISPO ip 300 .

can you please help me out with the solution.
Reply With Quote
  #11 (permalink)  
Old 2006-10-04
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,616
Rep Power: 4
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: SmartView Tracker not receiving logs

Quote:
Originally Posted by kranti View Post
can you please help me out with the solution.
take a look at a fw monitor to see if the logs are making it:

fw monitor -e 'accept src=<ip of gateway> or dst=<ip of gateway>;'
Reply With Quote
  #12 (permalink)  
Old 2007-10-05
Wonzling Wonzling is offline
Junior Member
 
Join Date: 2006-02-13
Location: Austria
Posts: 12
Rep Power: 0
Wonzling has an average reputation (10+)
Default Re: SmartView Tracker not receiving logs

I had the same problem, that the SmartView Tracker wasn't showing any log files. The problem was resulting from a policy that I imported from another Checkpoint-Firewall via the upgrade_tools on the command line. Afterwards the interfaces (which were basically the same, but had different names) couldn't be routed to.

After a simple 'Get Topology' under topology in the Checkpoint Object in the Dashboard the interfaces were named correctly and the logs started showing up in the tracker again.

Hope this is of some help to you guys.

cheers from Austria

W.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 17:07.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0