<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Checkpoint Bandwidth utilization check for the uneven spike in the traffic . in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Bandwidth-utilization-check-for-the-uneven-spike-in/m-p/133977#M20009</link>
    <description>&lt;P&gt;Try running the&amp;nbsp;&lt;STRONG&gt;fw ctl multik print_heavy_conn&lt;/STRONG&gt; command&amp;nbsp;every day, it will show all connections that were classified by the firewall as "heavy" (a.k.a. an elephant flow) over the last 24 hours.&amp;nbsp; It won't show the top connections per se, but will help identify any bandwidth-hogging connections historically.&amp;nbsp; To clarify what constitutes a "heavy" connection see here:&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk164215&amp;amp;partition=Advanced&amp;amp;product=CoreXL," target="_blank"&gt;sk164215: How to Detect and Handle Heavy Connections&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 13 Nov 2021 21:43:49 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2021-11-13T21:43:49Z</dc:date>
    <item>
      <title>Checkpoint Bandwidth utilization check for the uneven spike in the traffic .</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Bandwidth-utilization-check-for-the-uneven-spike-in/m-p/133778#M19932</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi Team ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need a way to understand if Checkpoint can show the data of Bandwidth consumed ( per source/network basis ) for the specific time of the day.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What are the possible ways i can verify the above.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Checkpoint version : R80.20&lt;/P&gt;&lt;P&gt;Blades enabled : Firewall , app control and content awareness&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2021 01:15:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Bandwidth-utilization-check-for-the-uneven-spike-in/m-p/133778#M19932</guid>
      <dc:creator>bookman</dc:creator>
      <dc:date>2021-11-11T01:15:26Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Bandwidth utilization check for the uneven spike in the traffic .</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Bandwidth-utilization-check-for-the-uneven-spike-in/m-p/133780#M19934</link>
      <description>&lt;P&gt;I believe smart view monitor can show this (under logs and monitor tab in dashboard). Do you have monitoring blade enabled on the firewall?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2021 01:34:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Bandwidth-utilization-check-for-the-uneven-spike-in/m-p/133780#M19934</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-11-11T01:34:22Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Bandwidth utilization check for the uneven spike in the traffic .</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Bandwidth-utilization-check-for-the-uneven-spike-in/m-p/133782#M19936</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Monitoring blade is not enabled ( not licensed ) , and the only blades that are enabled in the gateway are&amp;nbsp;&lt;SPAN&gt;Firewall , app control and content awareness.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Do we have any other options please ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2021 01:40:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Bandwidth-utilization-check-for-the-uneven-spike-in/m-p/133782#M19936</guid>
      <dc:creator>bookman</dc:creator>
      <dc:date>2021-11-11T01:40:37Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Bandwidth utilization check for the uneven spike in the traffic .</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Bandwidth-utilization-check-for-the-uneven-spike-in/m-p/133785#M19938</link>
      <description>&lt;P&gt;Sorry, I saw you mentioned that in the description as far as blades, my bad. Hm, not really sure without monitoring blade, but I can test it in the lab tomorrow. Because, quite honestly, I dont believe there is an easy way (or any way for that matter) to filter for something like this from regular logs, but will confirm.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2021 01:43:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Bandwidth-utilization-check-for-the-uneven-spike-in/m-p/133785#M19938</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-11-11T01:43:09Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Bandwidth utilization check for the uneven spike in the traffic .</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Bandwidth-utilization-check-for-the-uneven-spike-in/m-p/133788#M19940</link>
      <description>&lt;P&gt;Thanks for your response. Very much appreciated.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2021 03:23:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Bandwidth-utilization-check-for-the-uneven-spike-in/m-p/133788#M19940</guid>
      <dc:creator>bookman</dc:creator>
      <dc:date>2021-11-11T03:23:36Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Bandwidth utilization check for the uneven spike in the traffic .</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Bandwidth-utilization-check-for-the-uneven-spike-in/m-p/133790#M19941</link>
      <description>&lt;P&gt;I see there is an option for bandwidth when searching in logs, but not sure what value to search for, as I never used it before. I will check more tomorrow and let you know. Its under field Other Fields: and then bandwidth,&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2021 03:45:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Bandwidth-utilization-check-for-the-uneven-spike-in/m-p/133790#M19941</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-11-11T03:45:47Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Bandwidth utilization check for the uneven spike in the traffic .</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Bandwidth-utilization-check-for-the-uneven-spike-in/m-p/133854#M19966</link>
      <description>&lt;P&gt;cpview on the gateway is one possibility, at least in real-time.&lt;BR /&gt;Make sure you are on a recent JHF.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2021 18:59:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Bandwidth-utilization-check-for-the-uneven-spike-in/m-p/133854#M19966</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-11-11T18:59:11Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Bandwidth utilization check for the uneven spike in the traffic .</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Bandwidth-utilization-check-for-the-uneven-spike-in/m-p/133872#M19973</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does the cpview also shows the historical bandwidth usage per source/dest ? If not do we have any other options like cpviewer and Smartview or any other options we can really on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp; That's correct there is a bandwidth option in the other fields but not sure what option to enter since even i haven't used that before.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Nov 2021 00:39:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Bandwidth-utilization-check-for-the-uneven-spike-in/m-p/133872#M19973</guid>
      <dc:creator>bookman</dc:creator>
      <dc:date>2021-11-12T00:39:02Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Bandwidth utilization check for the uneven spike in the traffic .</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Bandwidth-utilization-check-for-the-uneven-spike-in/m-p/133874#M19974</link>
      <description>&lt;P&gt;I did not forget about you, just been a busy day, apologies. I had been trying to figure out how to actually run that filter, but no luck so far. Will definitely work on it Friday morning and update you in this thread.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 12 Nov 2021 01:35:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Bandwidth-utilization-check-for-the-uneven-spike-in/m-p/133874#M19974</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-11-12T01:35:30Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Bandwidth utilization check for the uneven spike in the traffic .</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Bandwidth-utilization-check-for-the-uneven-spike-in/m-p/133875#M19975</link>
      <description>&lt;P&gt;No worries , really appreciate your kind support.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Nov 2021 02:14:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Bandwidth-utilization-check-for-the-uneven-spike-in/m-p/133875#M19975</guid>
      <dc:creator>bookman</dc:creator>
      <dc:date>2021-11-12T02:14:33Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Bandwidth utilization check for the uneven spike in the traffic .</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Bandwidth-utilization-check-for-the-uneven-spike-in/m-p/133877#M19977</link>
      <description>&lt;P&gt;cpview has historical options (i.e. you can see what was going on at a given point in time), but I don't know that it tracks specific top connections over time or not.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Nov 2021 03:14:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Bandwidth-utilization-check-for-the-uneven-spike-in/m-p/133877#M19977</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-11-12T03:14:51Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Bandwidth utilization check for the uneven spike in the traffic .</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Bandwidth-utilization-check-for-the-uneven-spike-in/m-p/133878#M19978</link>
      <description>&lt;P&gt;Thank you for your response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So what are the other options we can rely on to check the historical bandwidth usage per source/network basis.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Nov 2021 03:17:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Bandwidth-utilization-check-for-the-uneven-spike-in/m-p/133878#M19978</guid>
      <dc:creator>bookman</dc:creator>
      <dc:date>2021-11-12T03:17:28Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Bandwidth utilization check for the uneven spike in the traffic .</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Bandwidth-utilization-check-for-the-uneven-spike-in/m-p/133937#M19993</link>
      <description>&lt;P&gt;Im really sorry, tried every possible option I could think of for that bandwidth setting and no luck : (. Maybe you could confirm with TAC or someone else here can chime in.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Nov 2021 13:49:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Bandwidth-utilization-check-for-the-uneven-spike-in/m-p/133937#M19993</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-11-12T13:49:00Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Bandwidth utilization check for the uneven spike in the traffic .</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Bandwidth-utilization-check-for-the-uneven-spike-in/m-p/133977#M20009</link>
      <description>&lt;P&gt;Try running the&amp;nbsp;&lt;STRONG&gt;fw ctl multik print_heavy_conn&lt;/STRONG&gt; command&amp;nbsp;every day, it will show all connections that were classified by the firewall as "heavy" (a.k.a. an elephant flow) over the last 24 hours.&amp;nbsp; It won't show the top connections per se, but will help identify any bandwidth-hogging connections historically.&amp;nbsp; To clarify what constitutes a "heavy" connection see here:&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk164215&amp;amp;partition=Advanced&amp;amp;product=CoreXL," target="_blank"&gt;sk164215: How to Detect and Handle Heavy Connections&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Nov 2021 21:43:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Bandwidth-utilization-check-for-the-uneven-spike-in/m-p/133977#M20009</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-11-13T21:43:49Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Bandwidth utilization check for the uneven spike in the traffic .</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Bandwidth-utilization-check-for-the-uneven-spike-in/m-p/134030#M20025</link>
      <description>&lt;P&gt;Thanks for your response.&lt;/P&gt;&lt;P&gt;Does the command help to identify the connection which had heavy flow a week ago ?&lt;/P&gt;&lt;P&gt;Since the issue occurred only once and usually this is occurring whenever the Microsoft patch upgrade over the systems ( happens once in a month ) . So basically wanted to know and get proof is this because of patch upgrade it happens or does any other traffic constituting to this.&lt;/P&gt;&lt;P&gt;Bandwidth spike occurrences are taking from the SolarWinds monitoring , and from the CP want to identify the historical bandwidth hogging connection for that particular time.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2021 06:53:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Bandwidth-utilization-check-for-the-uneven-spike-in/m-p/134030#M20025</guid>
      <dc:creator>bookman</dc:creator>
      <dc:date>2021-11-15T06:53:37Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Bandwidth utilization check for the uneven spike in the traffic .</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Bandwidth-utilization-check-for-the-uneven-spike-in/m-p/134067#M20034</link>
      <description>&lt;P&gt;No just the last 24 hours and that can't duration be changed, which is why I suggested running it once a day.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2021 12:51:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Bandwidth-utilization-check-for-the-uneven-spike-in/m-p/134067#M20034</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-11-15T12:51:48Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Bandwidth utilization check for the uneven spike in the traffic .</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Bandwidth-utilization-check-for-the-uneven-spike-in/m-p/134137#M20064</link>
      <description>&lt;P&gt;Another way to catch real time high bandwidth sources is to run a tcpdump on the gateway for say 10 seconds and then export it to wireshark and sort by Bytes Down&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 09:44:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Bandwidth-utilization-check-for-the-uneven-spike-in/m-p/134137#M20064</guid>
      <dc:creator>Antonis_Hassiot</dc:creator>
      <dc:date>2021-11-16T09:44:12Z</dc:date>
    </item>
  </channel>
</rss>

