> Source: [sk121412](https://support.checkpoint.com/results/sk/sk121412)

# sk121412 - Logs or Alerts are  sent to both Primary and Backup log servers defined under the "Logs" section of Firewall object in SmartDashboard

| Property | Value |
|----------|-------|
| Solution ID | sk121412 |
| Date Created | 2017-11-13 |
| Last Modified | 2017-11-16 |
| Technical Level | Advanced |
| OS | Gaia |

## Symptoms

- * Logs and Alerts are sent to both Primary and Backup log server defined under the "Logs" section of Firewall object in SmartDashboard.
* The output of *#netstat -nap \| grep 257* from the Security Gateway shows that the connection with at least one of the Primary Log servers was not established and is in "SYN_SENT" state. e.g. primary server 10.3.x.y as shown below:  
  \[Expert@Frewall1:0\]# netstat -nap \| grep 257  
  .  
  ..  
  tcp 0 1 10.114.16.50:42048 10.3.x.y:257 SYN_SENT 4972/fwd
* The content of the Masters file in the Security Gateway reflects the exact configurations as in the GUI "Logs" section and shows that there was no customization for its content, for example:  
  \[Expert@TRGEBXF001:0\]# cat /opt/CPsuite-R77/fw1/conf/masters  
  \[Policy\]  

  \[Log\]  
  \<1st Primary Log server object name\>  
  \[Alert\]  
  \<1st Primary Log server object name\>  
  \<2nd Primary Log server object name\> which is NOT reachable from the Firewall.  
  \[Backup\]  

  #cat /opt/CPsuite-R77/fw1/conf/masters
* Telnet connection over TCP port 257 from the Security Gateway to the unreachable Primary Log server could not be established, For example: \[Expert@Frewall1:0\]#telnet 257  
  trying ...

## Cause

Several Primary log servers are defined in the 'Firewall object \> Logs \> upper Log server section', where at least one of them is not reachable from the Firewall.

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk121412/sk121412_11711150650.png)

By design, the Firewall sends the logs to all the available Primary Log servers, in addition to the Backup Log servers defined in the lower section of 'Firewall object \> Logs'.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
