sk181609 - Security Gateway forwards logs to the real IP address of the Management Server instead of the public (NATed) IP address

Security Gateway forwards logs to the real IP address of the Management Server instead of the public (NATed) IP address

Product: Cloud Firewall, Security Gateways
Version: R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82
OS: Gaia
Platform: AWS, Azure
Last Modified: 2026-04-27

Symptoms

Solution

This problem was fixed. The fix is included in:

After upgrading the Security Gateway, do this manual configuration.

Configuration

  1. Connect to the command line on the Security Gateway / each Cluster Member.

  2. Log in to the Expert mode.

  3. On a VSX Gateway / VSX Cluster Member, go to the context of the applicable Virtual System:

    # vsenv <VSID>
    
  4. Run the applicable command:

    1. To force the Security Gateway to forward logs only to the public (NATed) IP address of the Management Server, run: 1.
      # sed -i.bak '/DLPDIR/a LOG_FORWARD_FORCE_NAT_ENV_VAR=1; export LOG_FORWARD_FORCE_NAT_ENV_VAR; hash 1>/dev/null 2>&1' "$CPDIR/tmp/.CPprofile.sh"
      # cpstop;cpstart
      
    2. To return to the initial behavior, where the Security Gateway forwards forwarded logs to the real IP address of the Management Server run: 1.
      # cp -v $CPDIR/tmp/.CPprofile.sh.bak $CPDIR/tmp/.CPprofile.sh
      # cpstop;cpstart
      

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level: General
Status: Approved by TAC
Date Created: 2023-11-20
Last Modified: 2026-04-27