<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Amount of traffic in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-traffic/m-p/146351#M23202</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I need to know how much traffic (GB or MB) has passed through our firewall in a year for example. Does anyone know how I can get this information?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Fri, 15 Apr 2022 15:15:03 GMT</pubDate>
    <dc:creator>yunier88</dc:creator>
    <dc:date>2022-04-15T15:15:03Z</dc:date>
    <item>
      <title>Amount of traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-traffic/m-p/102892#M10058</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;Do anyone knows if its possible to check the amount of traffic generate from specific servers behind the firewall?&lt;BR /&gt;In this case how many Mbit or traffic amount in GB, i guess netflow would do the trick...&lt;BR /&gt;&lt;BR /&gt;Am aware how to check number of connections/logs etc.&lt;BR /&gt;But is it possible to get traffic numbers?&lt;BR /&gt;&lt;BR /&gt;Will smartevent catch this or is that limited to webtraffic such as HTTP/HTTPS?&lt;BR /&gt;We are running VSX, R80.30 HFA219.&lt;/P&gt;&lt;P&gt;As far as iknow you need to configure generic netflow and not able to have one destination per VS.&lt;BR /&gt;So this complicate things within VSX aswell.&lt;/P&gt;&lt;P&gt;Regards&lt;BR /&gt;Magnus&lt;/P&gt;</description>
      <pubDate>Sun, 22 Nov 2020 14:15:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-traffic/m-p/102892#M10058</guid>
      <dc:creator>Magnus-Holmberg</dc:creator>
      <dc:date>2020-11-22T14:15:29Z</dc:date>
    </item>
    <item>
      <title>Re: Amount of traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-traffic/m-p/102898#M10059</link>
      <description>&lt;P&gt;Magnus,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe it is possible from SmartEvent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;smartevent has a particular generic template with total bandwidth etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;with some modification to the template, I believe you could achieve this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will try create this for you at some point tomorrow if you don’t beat me to it!&lt;/P&gt;</description>
      <pubDate>Sun, 22 Nov 2020 14:31:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-traffic/m-p/102898#M10059</guid>
      <dc:creator>JackPrendergast</dc:creator>
      <dc:date>2020-11-22T14:31:53Z</dc:date>
    </item>
    <item>
      <title>Re: Amount of traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-traffic/m-p/102903#M10060</link>
      <description>&lt;P&gt;hehe thanks!&lt;BR /&gt;Smartevent is not my strong side so am sure you will beat me to it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;Only ever used it for websurfing for clients so haven't tried within the network so to say.&lt;/P&gt;</description>
      <pubDate>Sun, 22 Nov 2020 14:43:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-traffic/m-p/102903#M10060</guid>
      <dc:creator>Magnus-Holmberg</dc:creator>
      <dc:date>2020-11-22T14:43:37Z</dc:date>
    </item>
    <item>
      <title>Re: Amount of traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-traffic/m-p/102912#M10061</link>
      <description>&lt;P&gt;Magnus,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here you go.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The report is abit rough cosmetically, but it will do the job.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me know if you want it tidying up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This will show the top sources on bandwidth usage. To search for the specific source you want, just simply do the usual search in the search bar - "src:xxx.xxx.xxx.xxx"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note - Make sure accounting is ticked under your log options for your rules!! This is a must! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.dropbox.com/s/zfd5rvp7wgjxnzp/Application_and_URL_Filtering_Nov_22__2020_7_47_36_PM.cpr?dl=0" target="_blank"&gt;https://www.dropbox.com/s/zfd5rvp7wgjxnzp/Application_and_URL_Filtering_Nov_22__2020_7_47_36_PM.cpr?dl=0&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Nov 2020 20:01:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-traffic/m-p/102912#M10061</guid>
      <dc:creator>JackPrendergast</dc:creator>
      <dc:date>2020-11-22T20:01:40Z</dc:date>
    </item>
    <item>
      <title>Re: Amount of traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-traffic/m-p/102914#M10062</link>
      <description>&lt;P&gt;Thats quick!, i will try to check it out during the week then.&lt;BR /&gt;Still need to install a smartevent box and add to the MDS/MLM &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Accounting on the rules..&amp;nbsp; That's a pain, 1000rules+ and already logging 50G+ per day.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;/Magnus&lt;/P&gt;</description>
      <pubDate>Sun, 22 Nov 2020 20:34:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-traffic/m-p/102914#M10062</guid>
      <dc:creator>Magnus-Holmberg</dc:creator>
      <dc:date>2020-11-22T20:34:19Z</dc:date>
    </item>
    <item>
      <title>Re: Amount of traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-traffic/m-p/102915#M10063</link>
      <description>&lt;P&gt;You should be able to directly attach the .cpr file to a message (or worst case, after zipped).&lt;/P&gt;</description>
      <pubDate>Sun, 22 Nov 2020 21:01:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-traffic/m-p/102915#M10063</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-11-22T21:01:34Z</dc:date>
    </item>
    <item>
      <title>Re: Amount of traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-traffic/m-p/103046#M10064</link>
      <description>&lt;P&gt;I tried attaching it directly and it stripped it out. Next time I’ll try zip it! Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 23 Nov 2020 19:58:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-traffic/m-p/103046#M10064</guid>
      <dc:creator>JackPrendergast</dc:creator>
      <dc:date>2020-11-23T19:58:32Z</dc:date>
    </item>
    <item>
      <title>Re: Amount of traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-traffic/m-p/103047#M10065</link>
      <description>&lt;P&gt;Accounting is necessary unfortunately. Do you have extended log on any of them rules? Maybe you could look at your logging to try reduce.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Much more and you may need to consider additional correlative units for SmartEvent if you want to use it heavily in production&lt;/P&gt;</description>
      <pubDate>Mon, 23 Nov 2020 20:00:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-traffic/m-p/103047#M10065</guid>
      <dc:creator>JackPrendergast</dc:creator>
      <dc:date>2020-11-23T20:00:27Z</dc:date>
    </item>
    <item>
      <title>Re: Amount of traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-traffic/m-p/103564#M10066</link>
      <description>&lt;P&gt;Now i have installed a smartevent server attached it to the global domain.&lt;BR /&gt;added the specific CMA/CLM within Initial settings correlation units and the CMA in object domains&lt;BR /&gt;Installed DB, changed all rules to accounting, left it a few hours but well more or less nothing. i get it like 30.000 events system status says OK.&lt;BR /&gt;Firewall is generating like 400.000 logs/hour&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Will this actually work with FW only? based on your file&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/40392"&gt;@JackPrendergast&lt;/a&gt;&amp;nbsp; am guessing i do need to activate application controll &amp;amp; url filtering aswell&lt;BR /&gt;In this case am looking for bandwidth uses within the check point between interfaces.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Magnus&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2020 20:41:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-traffic/m-p/103564#M10066</guid>
      <dc:creator>Magnus-Holmberg</dc:creator>
      <dc:date>2020-11-27T20:41:53Z</dc:date>
    </item>
    <item>
      <title>Re: Amount of traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-traffic/m-p/103575#M10067</link>
      <description>&lt;P&gt;Shouldnt have to enable URLF&amp;amp;APPC - should be fine with FW only with logs set to accounting&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unless I am wrong.. but that should work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me know &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 28 Nov 2020 14:29:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-traffic/m-p/103575#M10067</guid>
      <dc:creator>JackPrendergast</dc:creator>
      <dc:date>2020-11-28T14:29:55Z</dc:date>
    </item>
    <item>
      <title>Re: Amount of traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-traffic/m-p/103577#M10068</link>
      <description>&lt;P&gt;Sadly not get it to work, so currently checking on the possibilitys to do it via netflow.&lt;/P&gt;</description>
      <pubDate>Sat, 28 Nov 2020 16:23:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-traffic/m-p/103577#M10068</guid>
      <dc:creator>Magnus-Holmberg</dc:creator>
      <dc:date>2020-11-28T16:23:16Z</dc:date>
    </item>
    <item>
      <title>Re: Amount of traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-traffic/m-p/146351#M23202</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I need to know how much traffic (GB or MB) has passed through our firewall in a year for example. Does anyone know how I can get this information?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 15 Apr 2022 15:15:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-traffic/m-p/146351#M23202</guid>
      <dc:creator>yunier88</dc:creator>
      <dc:date>2022-04-15T15:15:03Z</dc:date>
    </item>
  </channel>
</rss>

