Hi, Thank you for your reply. Yes all the same port forwarding rules have been set up again (as it cleared those but kept the outgoing rules when I switched it over). I didn't notice but in your example where yours shows "MX1" ours only shows our WiFi AP names, there are none for the MX at all since I switched it over. Looking back I can see it used to log the MX flows. Ive tried factory defaulting it this morning and getting the settings pushed down to it again. Ive tried removing and re-adding the syslog server, which is receiving but only "WiFi" flows, urls, events. On the syslog settings it is currently set to send out "Flows, URLs, Security Events, Appliance event log, Switch event log, Air Marshal events and Wireless event log". On the Firewall settings Inbound firewall logging is enabled and all of our 23 outbound rules all have logging enabled. I cant find any other logging options that might need turning on? We are currently on MX14.45. Thanks Gary
... View more