Solved

Logging on Watchguard x5000

Posted on 2006-11-20
3
1,045 Views
Last Modified: 2013-11-16
I am trying to enable logging on our watchguard x5000 firewall. I have a log server and WSM8.3 running on the same client desktop. My log current path is:
 c:/documents and settings/allusers/shared watchguard/logs
I have configured logging on policy manager and saved settings in the normal way. I check in Firebox system manager and in the bottom left hand there is a detail panel which states that  "log server: None"  The firebox crashes every two to three days and i am trying to find out what is causing it by looking at the logs, but i cannot at this stage do so. Can anyone offer any advice?

Thanking you in advance

Eddie
0
Comment
Question by:edjbartos
3 Comments
 
LVL 13

Accepted Solution

by:
hstiles earned 250 total points
ID: 17987702
Is the firewall running WFS or Fireware Pro?

Could you open a command prompt on your PC and type netstat -an and check the results.  Let's say your log server has IP 192.168.1.5 and your firebox has IP 192.168.1.1, What you should see is

TCP 192.168.1.5:4107              192.168.1.1:XXXXX (some high value port)         ESTABLISHED - This appears to be SOHO, Edge and possibly WFS devices

TCP 192.168.1.5:4115              192.168.1.1:XXXXX (some high value port)         ESTABLISHED - This appears to be Core, Peak or maybe just Fireware Pro devices

If not, do you see TCP 0.0.0.0:4107 and TCP 0.0.0.0:4115?  This indicates that the log server is running.

Is the log machine behind the trusted interface of the Firebox?  If not, you'll need to add a Watxchguard Logging Rule.

Next, check the log security phrase and make sure it's correct.

Finally, it might be worth you re-flashing the FIrebox.  Make sure your configuration is backed up and run the quick set up wizard again to reload the image.
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Suggested Solutions

The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
In this seventh video of the Xpdf series, we discuss and demonstrate the PDFfonts utility, which lists all the fonts used in a PDF file. It does this via a command line interface, making it suitable for use in programs, scripts, batch files — any pl…
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now