sk170331 - Security Gateway stops logging locally or to assigned Log Servers

Security Gateway stops logging locally or to assigned Log Servers

Product: ClusterXL, Security Gateways
Version: R80.30 (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82
OS: Gaia
Last Modified: 2025-01-20

Symptoms

Cause

The file fw.logtrack file on Security Gateway / Cluster Member is corrupted. This may be caused by extremely high load on the FWD daemon.

Solution

Critical: You must schedule a maintenance window to perform this procedure. Because this procedure stops the FWD daemon, it may cause a traffic outage, and a failover in a cluster.

  1. Connect to the command line on the Security Gateway / Cluster Member.

  2. Log in to the Expert mode

  3. Terminate the FWD daemon:

    cpwd_admin stop -name FWD -path "$FWDIR/bin/fw" -command "fw kill fwd"
    
  4. Delete the corrupted fw.logtrack file:

    rm -i $FWDIR/log/fw.logtrack
    
  5. Start the FWD daemon:

    cpwd_admin start -name FWD -path "$FWDIR/bin/fw" -command "fwd"
    
  6. Examine the local logging - the sizes of the local log files must change:

    watch -d -n 1 "ls -l $FWDIR/log/fw.log*"
    
  7. Examine the remote logging - SmartConsole must show logs from this Security Gateway / Cluster Member.

This problem was fixed. The fix is included in:

If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.

Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.

Part 1 - Delete the corrupted fw.logtrack file:

Part 2 - Configure an environment variable:

  1. Connect to the command line on the Security Gateway / each Cluster Member.

  2. Log in to the Expert mode

  3. Back up the current $CPDIR/tmp/.CPprofile.sh file:

    cp -v $CPDIR/tmp/.CPprofile.sh{,_BKP}
    
  4. Edit the current $CPDIR/tmp/.CPprofile.sh file:

    vi $CPDIR/tmp/.CPprofile.sh
    
  5. Add this line - somewhere between the existing environment variables, and not at the end of the file:

    KLOG_CONVERTER_ENV_VAR=800; export KLOG_CONVERTER_ENV_VAR ; hash 1>/dev/null 2>&1
    
  6. Save the changes in the file and exit Vi editor.

  7. Reboot the Security Gateway / each Cluster Member.

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level: General
Status: Approved by TAC
Date Created: 2020-11-04
Last Modified: 2025-01-20