SMP can't show FW log

2024-12-26 17:02:57 Published
  • 0 Followed
  • 0Collected ,2350Browsed

Network Topology

SMP-FW

Problem Description

When SMP is just deployed, customers can query the firewall log information, but after a period of time, no firewall logs can be seen, as shown in the following figure:

Process Analysis

1.       First, capture the packet in the SMP background to confirm whether the log message sent by the firewall has been received:

2.       Confirm on SMP that the IP address of the added device is consistent with the source IP address of the log, because SMP receives logs based on IP address:

3.       Checking the device time, we found that there was a three-hour time difference between the device time and the browser time. Therefore, when viewing the logs on the SMP, we selected the time range as the last 24 hours, and then we could view the log information:


Solution

By default, the timestamp of the customlog output by the firewall is Greenwich Mean Time. The time displayed by the SMP after receiving the log will be displayed according to the PC time obtained by the browser. Therefore, if the PC time obtained by the browser is inconsistent with the device time, the security policy log cannot be displayed directly. You need to adjust the time range to view the log.

Please rate this case:   
0 Comments

No Comments

Add Comments: