> Source: [sk111742](https://support.checkpoint.com/results/sk/sk111742)

# sk111742 - Security Management Server cannot receive logs from Security Gateways due to timeout

| Property | Value |
|----------|-------|
| Solution ID | sk111742 |
| Date Created | 2016-11-24 |
| Last Modified | 2020-12-27 |
| Technical Level | Advanced |
| Products | Security Management Server |
| Versions | R82.10, R82, R81.20, R82.20 |

## Symptoms

- * The Security Management Server cannot receive logs from Gateways due to timeout.   

* Many fw switch logs are stored on local Gateways but the `fw.log` file does not increase. It seems that the Gateway does an automatic log-switch on the local.  

* The output of `netstat` shows:

  ```
  
  tcp        9      0 10.29.254.1:257             10.29.250.36:55820          CLOSE_WAIT  -                   
  ...                   
  tcp        9      0 10.29.254.1:257             10.29.250.36:60992          CLOSE_WAIT  -                   
  tcp        9      0 10.29.254.1:257             10.29.250.36:38486          CLOSE_WAIT  -                   
  tcp        0      0 10.29.254.1:48090           10.29.250.36:18192          ESTABLISHED 28081/status_proxy  
  tcp        9      0 10.29.254.1:257             10.29.250.36:50622          CLOSE_WAIT  -     
  ```

* The `fwd.elg` file shows:

  ```
  
  [FWD PID]@FW-1[DATE TIME] fwclient_connected: SIC Error for log_collection: timeout elapsed during authentication protocol. +++++
  [FWD PID]@FW-1[DATE TIME] fwclient_connected: connection failed
  [FWD PID]@FW-1[DATE TIME] log_collection_connect_event: connection failed
  [FWD PID]@FW-1[DATE TIME] FreeScheduledLogForwardEvent: updating the event status to FAILED
  ```

## Cause

There is a "Log forwarding" setting enabled in SmartDashboard that forwards logs to the same Security Management Server as the log setting. When the Security Gateway prepares to send local logs to the Security Management server / Log Server, it reviews all locally stored logs. If there are many logs on the local, the reviewing process takes a long time and may time out.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
