sk170331 - Security Gateway stops logging locally or to assigned Log Servers
Security Gateway stops logging locally or to assigned Log Servers
Product: ClusterXL, Security Gateways
Version: R80.30 (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82
OS: Gaia
Last Modified: 2025-01-20
Symptoms
- Security Gateway / Cluster Member stops logging locally or to configured Log Servers.
- "
FwKluProcessLogEx: fail to convert klog buffer to unified fragment" line appears repeatedly in the$FWDIR/log/fwd.elglog file on a Security Gateway / Cluster Member.
Cause
The file fw.logtrack file on Security Gateway / Cluster Member is corrupted. This may be caused by extremely high load on the FWD daemon.
Solution
Critical: You must schedule a maintenance window to perform this procedure. Because this procedure stops the FWD daemon, it may cause a traffic outage, and a failover in a cluster.
Connect to the command line on the Security Gateway / Cluster Member.
Log in to the Expert mode
Terminate the FWD daemon:
cpwd_admin stop -name FWD -path "$FWDIR/bin/fw" -command "fw kill fwd"Delete the corrupted fw.logtrack file:
rm -i $FWDIR/log/fw.logtrackStart the FWD daemon:
cpwd_admin start -name FWD -path "$FWDIR/bin/fw" -command "fwd"Examine the local logging - the sizes of the local log files must change:
watch -d -n 1 "ls -l $FWDIR/log/fw.log*"Examine the remote logging - SmartConsole must show logs from this Security Gateway / Cluster Member.
This problem was fixed. The fix is included in:
- Check Point Quantum R82
- Jumbo Hotfix Accumulator for R81.20 starting from Take 54
- Jumbo Hotfix Accumulator for R81.10 starting from Take 141
- Jumbo Hotfix Accumulator for R81 starting from Take 99
- Jumbo Hotfix Accumulator for R80.40 starting from Take 211
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
Part 1 - Delete the corrupted fw.logtrack file:
Part 2 - Configure an environment variable:
Connect to the command line on the Security Gateway / each Cluster Member.
Log in to the Expert mode
Back up the current $CPDIR/tmp/.CPprofile.sh file:
cp -v $CPDIR/tmp/.CPprofile.sh{,_BKP}Edit the current $CPDIR/tmp/.CPprofile.sh file:
vi $CPDIR/tmp/.CPprofile.shAdd this line - somewhere between the existing environment variables, and not at the end of the file:
KLOG_CONVERTER_ENV_VAR=800; export KLOG_CONVERTER_ENV_VAR ; hash 1>/dev/null 2>&1Save the changes in the file and exit Vi editor.
Reboot the Security Gateway / each Cluster Member.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2020-11-04
Last Modified: 2025-01-20