<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Getting top used rules via command line in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Getting-top-used-rules-via-command-line/m-p/161765#M28679</link>
    <description>&lt;P&gt;Thanks G, but thats only for Windows, this command was done from the fw itself.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Thu, 10 Nov 2022 14:01:57 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2022-11-10T14:01:57Z</dc:date>
    <item>
      <title>Getting top used rules via command line</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Getting-top-used-rules-via-command-line/m-p/161759#M28677</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;
&lt;P&gt;Apologies if this was answered before, but I remember while back, I always used to run command that would show me top 10 used rules on the firewall, but cant recall now what it was, as its been probably close to 10 years since I ran it. I know connstat, but thats only for windows. I also tried cpstat blades, but it does not show me anything there.&lt;/P&gt;
&lt;P&gt;I think it was some sort of flag with fw tab, but IM not sure. If someone has an idea, would appreciate any feedback.&lt;/P&gt;
&lt;P&gt;Tx as always!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Had a look at below, but not exactly what Im after:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/How-to-see-what-firewall-rules-match-some-traffic/td-p/18565" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/How-to-see-what-firewall-rules-match-some-traffic/td-p/18565&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_NextGenSecurityGateway_Guide/Topics-FWG/CLI/fw-ctl-conntab.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_NextGenSecurityGateway_Guide/Topics-FWG/CLI/fw-ctl-conntab.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 13:59:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Getting-top-used-rules-via-command-line/m-p/161759#M28677</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-10T13:59:34Z</dc:date>
    </item>
    <item>
      <title>Re: Getting top used rules via command line</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Getting-top-used-rules-via-command-line/m-p/161763#M28678</link>
      <description>&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk85780&amp;amp;partition=Advanced&amp;amp;product=Other" target="_blank"&gt;sk85780: How to use the 'connstat' utility&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 13:57:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Getting-top-used-rules-via-command-line/m-p/161763#M28678</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-11-10T13:57:51Z</dc:date>
    </item>
    <item>
      <title>Re: Getting top used rules via command line</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Getting-top-used-rules-via-command-line/m-p/161765#M28679</link>
      <description>&lt;P&gt;Thanks G, but thats only for Windows, this command was done from the fw itself.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 14:01:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Getting-top-used-rules-via-command-line/m-p/161765#M28679</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-10T14:01:57Z</dc:date>
    </item>
    <item>
      <title>Re: Getting top used rules via command line</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Getting-top-used-rules-via-command-line/m-p/161766#M28680</link>
      <description>&lt;DIV class=""&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_NextGenSecurityGateway_Guide/Topics-FWG/CLI/cpstat.htm" target="_self"&gt;&lt;STRONG&gt;&lt;CODE&gt;cpstat blades&lt;/CODE&gt;&lt;/STRONG&gt;&lt;/A&gt;&lt;LI-CODE lang="markup"&gt;# cpstat blades

Packets accepted :          766249577
Packets dropped :           24321576
Peak number of connections: 19013
Number of connections:      5797

Top Rule Hits
-----------------------
|rule index|rule count|
-----------------------
|Rule 24   |    170186|
|Rule 36   |     59828|
|Rule 2    |     27792|
|Rule 15   |      1234|
|Rule 18   |      1026|
-----------------------&lt;/LI-CODE&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 10 Nov 2022 15:01:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Getting-top-used-rules-via-command-line/m-p/161766#M28680</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2022-11-10T15:01:48Z</dc:date>
    </item>
    <item>
      <title>Re: Getting top used rules via command line</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Getting-top-used-rules-via-command-line/m-p/161768#M28681</link>
      <description>&lt;P&gt;Weird...run it on vmware and actual 6000 series appliance, nothing.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 14:12:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Getting-top-used-rules-via-command-line/m-p/161768#M28681</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-10T14:12:41Z</dc:date>
    </item>
    <item>
      <title>Re: Getting top used rules via command line</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Getting-top-used-rules-via-command-line/m-p/161769#M28682</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;This command must be applied on the GW?&lt;BR /&gt;Or is it on the SMS?&lt;/P&gt;&lt;P&gt;Greetings.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 14:14:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Getting-top-used-rules-via-command-line/m-p/161769#M28682</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2022-11-10T14:14:50Z</dc:date>
    </item>
    <item>
      <title>Re: Getting top used rules via command line</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Getting-top-used-rules-via-command-line/m-p/161770#M28683</link>
      <description>&lt;P&gt;I have run the command in a Standalone environment, which is on an OPEN SERVER, and I get no results either.&lt;/P&gt;&lt;P&gt;It is very strange. &lt;span class="lia-unicode-emoji" title=":persevering_face:"&gt;😣&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 14:21:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Getting-top-used-rules-via-command-line/m-p/161770#M28683</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2022-11-10T14:21:38Z</dc:date>
    </item>
    <item>
      <title>Re: Getting top used rules via command line</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Getting-top-used-rules-via-command-line/m-p/161771#M28684</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Gateway&lt;/STRONG&gt;, of course.&lt;BR /&gt;On &lt;STRONG&gt;managements&lt;/STRONG&gt; you can use this command:&lt;BR /&gt;&lt;STRONG&gt;&lt;CODE&gt;psql_client monitoring postgres -c "select hits,rule_uid,netobj_name,policy_type from hitcount order by hits DESC"&lt;/CODE&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 14:25:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Getting-top-used-rules-via-command-line/m-p/161771#M28684</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2022-11-10T14:25:34Z</dc:date>
    </item>
    <item>
      <title>Re: Getting top used rules via command line</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Getting-top-used-rules-via-command-line/m-p/161774#M28688</link>
      <description>&lt;P&gt;Its cloud instance, so no ssh access.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 14:53:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Getting-top-used-rules-via-command-line/m-p/161774#M28688</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-10T14:53:32Z</dc:date>
    </item>
    <item>
      <title>Re: Getting top used rules via command line</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Getting-top-used-rules-via-command-line/m-p/161776#M28690</link>
      <description>&lt;P&gt;Btw, that command shows me top 5 rules for one customer using 6200, but another using 6400, nothing...wonder why. Also, my lab fw, in esxi, shows nothing for top rules.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 14:55:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Getting-top-used-rules-via-command-line/m-p/161776#M28690</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-10T14:55:45Z</dc:date>
    </item>
    <item>
      <title>Re: Getting top used rules via command line</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Getting-top-used-rules-via-command-line/m-p/161777#M28691</link>
      <description>&lt;P&gt;So your Management is Smart-1 Cloud and your gateways are on-prem?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 14:56:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Getting-top-used-rules-via-command-line/m-p/161777#M28691</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2022-11-10T14:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: Getting top used rules via command line</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Getting-top-used-rules-via-command-line/m-p/161781#M28694</link>
      <description>&lt;P&gt;Correct, for the customer, but in my lab, its all on prem.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 15:22:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Getting-top-used-rules-via-command-line/m-p/161781#M28694</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-10T15:22:40Z</dc:date>
    </item>
    <item>
      <title>Re: Getting top used rules via command line</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Getting-top-used-rules-via-command-line/m-p/161782#M28695</link>
      <description>&lt;P&gt;Was hit count enabled on all these ?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 15:26:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Getting-top-used-rules-via-command-line/m-p/161782#M28695</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-11-10T15:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: Getting top used rules via command line</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Getting-top-used-rules-via-command-line/m-p/161784#M28696</link>
      <description>&lt;P&gt;Yes sir Gunther...as a matter of fact, enabled for the last 2 years, which is maximum.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 15:38:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Getting-top-used-rules-via-command-line/m-p/161784#M28696</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-10T15:38:52Z</dc:date>
    </item>
  </channel>
</rss>

