> Source: [sk103760](https://support.checkpoint.com/results/sk/sk103760)

# sk103760 - Security Gateway continues to log locally and does not attempt to reconnect to Security Management Server / Log Server

| Property | Value |
|----------|-------|
| Solution ID | sk103760 |
| Date Created | 2014-12-23 |
| Last Modified | 2020-05-14 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * After restarting Security Management Server / Domain Management Server / Log Server, logs from Security Gateways are not received - Security Gateways continue to log locally.

* Output of '*netstat -anp*' command on both sides does not show an established connection on TCP port 257 (on which firewall logs are transferred).

* Restarting FWD daemon on Security Gateways, or Installing Policy / Installing Database in SmartDashboard resolves the issue.

* Debug of FWD daemon (per [sk86321](http://supportcontent.checkpoint.com/solutions?id=sk86321)) on Security Gateways during the issue repeatedly shows the following lines:

  ```
  
  log_add_e: waiting for connecting callback (log_connected) to be read
  log_add_e: Write locally ! log record number = XXX
  ```

## Cause

During high CPU load on Security Management Server / Log Server when logs are being sent to it, the Security Gateway's FWD daemon (which is responsible for log transfer), has a keep-alive mechanism for checking communication with its "Log Server". Once communication breaks and after a couple of keep-alive rotations, Security Gateway will start logging locally to the $FWDIR/log/fw.log file.

This behavior is by design (Note: the FireWall log file ($FWDIR/log/fw.log) can be fetched from the Security Gateway in the SmartView Tracker, once communication returns - either by the Log Forwarding option, or by Remote Files Management).

In addition, an issue was discovered with reconnecting mechanism on Security Gateway.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
