<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does the HA Passive PA-VM Firewall forwards the logs to syslog server in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/does-the-ha-passive-pa-vm-firewall-forwards-the-logs-to-syslog/m-p/444725#M1373</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've just opened the ticket with the TAC. Also on the other hand I'd performed all the above steps mentioned by&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp;prior coming to this live-community forum.&lt;BR /&gt;&lt;BR /&gt;The behavior is, no packets were observed at the Passive device. Had a multiple sessions with the TAC. Even on a remote-session, the TAC couldn't see any packets being forwarded at the Passive unit.&lt;BR /&gt;&lt;BR /&gt;Restarted the management-server, device-server, vardata-receiver, log-rcvr, Also restarted the syslog-ng. The Passive unit's &lt;STRONG&gt;tcpdump&lt;/STRONG&gt; and &lt;STRONG&gt;debug log-receiver statistics&lt;/STRONG&gt; didn't show any clue about the packet-forward to syslog-server. So none of the above activities has helped.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Post couple of weeks, TAC has again joined the call. And interestingly, without doing anything on Passive Unit, now the&amp;nbsp;&lt;STRONG&gt;tcpdump&lt;/STRONG&gt;&amp;nbsp;output show that the packets are being forwarded to the syslog-server. While the &lt;STRONG&gt;debug log-receiver statistics&amp;nbsp;&lt;/STRONG&gt;command doesn't show any numbers incrementing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Muruganandham SP&lt;/P&gt;</description>
    <pubDate>Mon, 01 Nov 2021 14:55:16 GMT</pubDate>
    <dc:creator>Muruganandham.SP</dc:creator>
    <dc:date>2021-11-01T14:55:16Z</dc:date>
    <item>
      <title>Does the HA Passive PA-VM Firewall forwards the logs to syslog server</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/does-the-ha-passive-pa-vm-firewall-forwards-the-logs-to-syslog/m-p/438771#M1346</link>
      <description>&lt;P&gt;Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have the pair of PA-VM deployed in HA A-P mode. The log-forwarding facility is enabled and the logs are being forwarded to the external Syslog-Server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is noticed that the Passive node is not sending any logs to the Syslog-Server. Only the Active node is sending the logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to understand that all the configurations are identical, and the communication to the Syslog-Server is directed from MGMT NIC directly to the servers on both the firewalls. So the Passive node must be sending the logs (system-log, config-log etc.).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please let us know the behavior.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;SPM&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 11:20:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/does-the-ha-passive-pa-vm-firewall-forwards-the-logs-to-syslog/m-p/438771#M1346</guid>
      <dc:creator>Muruganandham.SP</dc:creator>
      <dc:date>2021-10-05T11:20:33Z</dc:date>
    </item>
    <item>
      <title>Re: Does the HA Passive PA-VM Firewall forwards the logs to syslog server</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/does-the-ha-passive-pa-vm-firewall-forwards-the-logs-to-syslog/m-p/438788#M1347</link>
      <description>&lt;P&gt;Thank you for your post&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/176427"&gt;@Muruganandham.SP&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since passive Firewall is not passing any traffic, you will not see any Traffic Log, Threat Log,.. etc, however System Log as well as Configuration Log will be generated and if configured correctly sent to external syslog server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since you mentioned that configuration is identical and active Firewall is sending logs to external syslog server as a next thing I would check settings that are not HA synchronized, for example DNS server IP address. If you have configured Syslog as FQDN make sure that passive Firewall can resolve the IP address.&lt;/P&gt;&lt;P&gt;Also check System logs to see any related events:&amp;nbsp;( eventid eq syslog-conn-status ).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 12:11:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/does-the-ha-passive-pa-vm-firewall-forwards-the-logs-to-syslog/m-p/438788#M1347</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-10-05T12:11:53Z</dc:date>
    </item>
    <item>
      <title>Re: Does the HA Passive PA-VM Firewall forwards the logs to syslog server</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/does-the-ha-passive-pa-vm-firewall-forwards-the-logs-to-syslog/m-p/438800#M1348</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp; Yes, the Passive node cannot write any Traffic/Threat logs unless he becomes an active. So it is expected not to see Traffic/Threat logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The concern here is, system-log config-log etc.&lt;BR /&gt;&lt;BR /&gt;Yes, we do have the proper reachability to the Syslog server, FQDN works fine, DNS settings are made correctly and works fine. HA status is 'In-Sync'.&lt;BR /&gt;&lt;BR /&gt;The system-log in Passive node states that the syslog-server is 'connected' (it shows the old date though, while the Active node shows two different dates with newer date)&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Syslog passive fw issue.jpg" style="width: 830px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36826i03AA747F3B672EAE/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Syslog passive fw issue.jpg" alt="Syslog passive fw issue.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 12:25:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/does-the-ha-passive-pa-vm-firewall-forwards-the-logs-to-syslog/m-p/438800#M1348</guid>
      <dc:creator>Muruganandham.SP</dc:creator>
      <dc:date>2021-10-05T12:25:24Z</dc:date>
    </item>
    <item>
      <title>Re: Does the HA Passive PA-VM Firewall forwards the logs to syslog server</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/does-the-ha-passive-pa-vm-firewall-forwards-the-logs-to-syslog/m-p/438806#M1349</link>
      <description>&lt;P&gt;Thank you for quick reply&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/176427"&gt;@Muruganandham.SP&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry if I ask silly question, but based on your screen shot, the destination IP address is: 127.0.0.1 which is reserved loopback IP address. It looks like it is sending logs to itself?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 12:54:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/does-the-ha-passive-pa-vm-firewall-forwards-the-logs-to-syslog/m-p/438806#M1349</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-10-05T12:54:53Z</dc:date>
    </item>
    <item>
      <title>Re: Does the HA Passive PA-VM Firewall forwards the logs to syslog server</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/does-the-ha-passive-pa-vm-firewall-forwards-the-logs-to-syslog/m-p/438809#M1350</link>
      <description>&lt;P&gt;1. Passive firewall will not forward logs until failover&lt;/P&gt;&lt;P&gt;2. However, this looks like you have configured transport protocol as TCP in syslog server profile and an internal connection is established to syslog-ng on port 2625 and this keeps popping up in system logs.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 13:04:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/does-the-ha-passive-pa-vm-firewall-forwards-the-logs-to-syslog/m-p/438809#M1350</guid>
      <dc:creator>asangra</dc:creator>
      <dc:date>2021-10-05T13:04:47Z</dc:date>
    </item>
    <item>
      <title>Re: Does the HA Passive PA-VM Firewall forwards the logs to syslog server</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/does-the-ha-passive-pa-vm-firewall-forwards-the-logs-to-syslog/m-p/438896#M1351</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="msedge_t3HHpp2Ib9.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36830iD0FE2CA2659B586F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="msedge_t3HHpp2Ib9.png" alt="msedge_t3HHpp2Ib9.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 16:29:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/does-the-ha-passive-pa-vm-firewall-forwards-the-logs-to-syslog/m-p/438896#M1351</guid>
      <dc:creator>Muruganandham.SP</dc:creator>
      <dc:date>2021-10-05T16:29:37Z</dc:date>
    </item>
    <item>
      <title>Re: Does the HA Passive PA-VM Firewall forwards the logs to syslog server</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/does-the-ha-passive-pa-vm-firewall-forwards-the-logs-to-syslog/m-p/438897#M1352</link>
      <description>&lt;P&gt;I have the Syslog configured with &lt;STRONG&gt;UDP&lt;/STRONG&gt; only. And I believe the Passive node should forward the &lt;STRONG&gt;system-log&lt;/STRONG&gt;, &lt;STRONG&gt;config-log&lt;/STRONG&gt; kind of logs to the Syslog-Server.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 16:31:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/does-the-ha-passive-pa-vm-firewall-forwards-the-logs-to-syslog/m-p/438897#M1352</guid>
      <dc:creator>Muruganandham.SP</dc:creator>
      <dc:date>2021-10-05T16:31:46Z</dc:date>
    </item>
    <item>
      <title>Re: Does the HA Passive PA-VM Firewall forwards the logs to syslog server</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/does-the-ha-passive-pa-vm-firewall-forwards-the-logs-to-syslog/m-p/438997#M1353</link>
      <description>&lt;P&gt;Thank you for update&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/176427"&gt;@Muruganandham.SP&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am running in my environment the same setup where Passive Firewall is sending System logs to syslog server and I can confirm that I can see logs on server side, so this should be definitely working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As next step to troubleshoot, I would advice to check detailed output from:&amp;nbsp;&lt;STRONG&gt;less mp-log syslog-ng.log&lt;/STRONG&gt; and take packet capture on management interface:&amp;nbsp;&lt;STRONG&gt;tcpdump filter "port 514"&lt;/STRONG&gt; (&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CleECAS)" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CleECAS)&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 22:45:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/does-the-ha-passive-pa-vm-firewall-forwards-the-logs-to-syslog/m-p/438997#M1353</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-10-05T22:45:24Z</dc:date>
    </item>
    <item>
      <title>Re: Does the HA Passive PA-VM Firewall forwards the logs to syslog server</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/does-the-ha-passive-pa-vm-firewall-forwards-the-logs-to-syslog/m-p/444725#M1373</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've just opened the ticket with the TAC. Also on the other hand I'd performed all the above steps mentioned by&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp;prior coming to this live-community forum.&lt;BR /&gt;&lt;BR /&gt;The behavior is, no packets were observed at the Passive device. Had a multiple sessions with the TAC. Even on a remote-session, the TAC couldn't see any packets being forwarded at the Passive unit.&lt;BR /&gt;&lt;BR /&gt;Restarted the management-server, device-server, vardata-receiver, log-rcvr, Also restarted the syslog-ng. The Passive unit's &lt;STRONG&gt;tcpdump&lt;/STRONG&gt; and &lt;STRONG&gt;debug log-receiver statistics&lt;/STRONG&gt; didn't show any clue about the packet-forward to syslog-server. So none of the above activities has helped.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Post couple of weeks, TAC has again joined the call. And interestingly, without doing anything on Passive Unit, now the&amp;nbsp;&lt;STRONG&gt;tcpdump&lt;/STRONG&gt;&amp;nbsp;output show that the packets are being forwarded to the syslog-server. While the &lt;STRONG&gt;debug log-receiver statistics&amp;nbsp;&lt;/STRONG&gt;command doesn't show any numbers incrementing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Muruganandham SP&lt;/P&gt;</description>
      <pubDate>Mon, 01 Nov 2021 14:55:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/does-the-ha-passive-pa-vm-firewall-forwards-the-logs-to-syslog/m-p/444725#M1373</guid>
      <dc:creator>Muruganandham.SP</dc:creator>
      <dc:date>2021-11-01T14:55:16Z</dc:date>
    </item>
  </channel>
</rss>

