Solved

Logging on Watchguard x5000

Posted on 2006-11-20
3
1,047 Views
Last Modified: 2013-11-16
I am trying to enable logging on our watchguard x5000 firewall. I have a log server and WSM8.3 running on the same client desktop. My log current path is:
 c:/documents and settings/allusers/shared watchguard/logs
I have configured logging on policy manager and saved settings in the normal way. I check in Firebox system manager and in the bottom left hand there is a detail panel which states that  "log server: None"  The firebox crashes every two to three days and i am trying to find out what is causing it by looking at the logs, but i cannot at this stage do so. Can anyone offer any advice?

Thanking you in advance

Eddie
0
Comment
Question by:edjbartos
3 Comments
 
LVL 13

Accepted Solution

by:
hstiles earned 250 total points
ID: 17987702
Is the firewall running WFS or Fireware Pro?

Could you open a command prompt on your PC and type netstat -an and check the results.  Let's say your log server has IP 192.168.1.5 and your firebox has IP 192.168.1.1, What you should see is

TCP 192.168.1.5:4107              192.168.1.1:XXXXX (some high value port)         ESTABLISHED - This appears to be SOHO, Edge and possibly WFS devices

TCP 192.168.1.5:4115              192.168.1.1:XXXXX (some high value port)         ESTABLISHED - This appears to be Core, Peak or maybe just Fireware Pro devices

If not, do you see TCP 0.0.0.0:4107 and TCP 0.0.0.0:4115?  This indicates that the log server is running.

Is the log machine behind the trusted interface of the Firebox?  If not, you'll need to add a Watxchguard Logging Rule.

Next, check the log security phrase and make sure it's correct.

Finally, it might be worth you re-flashing the FIrebox.  Make sure your configuration is backed up and run the quick set up wizard again to reload the image.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Wikipedia defines 'Script Kiddies' in this informal way: "In hacker culture, a script kiddie, occasionally script bunny, skiddie, script kitty, script-running juvenile (SRJ), or similar, is a derogatory term used to describe those who use scripts or…
The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
This tutorial gives a high-level tour of the interface of Marketo (a marketing automation tool to help businesses track and engage prospective customers and drive them to purchase). You will see the main areas including Marketing Activities, Design …
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…

803 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question