<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Delete rules without traffic R81.10 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/198389#M37136</link>
    <description>&lt;P&gt;Algosec, too.&lt;/P&gt;</description>
    <pubDate>Mon, 20 Nov 2023 14:05:36 GMT</pubDate>
    <dc:creator>Sven_Glock</dc:creator>
    <dc:date>2023-11-20T14:05:36Z</dc:date>
    <item>
      <title>Delete rules without traffic R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194271#M36146</link>
      <description>&lt;P&gt;Hello, everyone.&lt;/P&gt;
&lt;P&gt;Is there any accurate way to identify which rules are currently "no longer used" in GW?&lt;/P&gt;
&lt;P&gt;I have a R81.10 console, but I have quite a few rules, in which I don't see HITS, but there are so many rules, and besides that, I'm not sure if the fact that a rule has no HITS, should make me assume that this rule can be removed.&lt;/P&gt;
&lt;P&gt;Is there any way to validate which rules are the only ones currently "in use"?&lt;/P&gt;
&lt;P&gt;Greetings.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2023 00:14:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194271#M36146</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-10-05T00:14:37Z</dc:date>
    </item>
    <item>
      <title>Re: Delete rules without traffic R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194272#M36147</link>
      <description>&lt;P&gt;I would say if rules show 0 hits, they are safe to remove. I found that in R81.10 and R81.20, those numbers are very accurate. From my extensive lab testing, I can confidently say that.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2023 00:23:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194272#M36147</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-05T00:23:34Z</dc:date>
    </item>
    <item>
      <title>Re: Delete rules without traffic R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194309#M36150</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;By default the column 'Hits', how long is it that 'filters' that option? 1, 2, 3 months?&lt;/P&gt;
&lt;P&gt;Is there a way to set this 'hits' value?&lt;/P&gt;
&lt;P&gt;Greetings&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2023 12:45:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194309#M36150</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-10-05T12:45:20Z</dc:date>
    </item>
    <item>
      <title>Re: Delete rules without traffic R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194311#M36151</link>
      <description>&lt;P&gt;See attached bro.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;From global properties, 2 years is the highest&amp;nbsp;value.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22694iA69196FC29914674/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2023 12:48:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194311#M36151</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-05T12:48:06Z</dc:date>
    </item>
    <item>
      <title>Re: Delete rules without traffic R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194418#M36179</link>
      <description>&lt;P&gt;You can retrieve the hit counts from API.&lt;BR /&gt;You can even make a decision to disable rules based on this information, similar to what this script does:&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/t5/API-CLI-Discussion/Disable-Delete-Rules-with-a-Zero-Hit-Count-MDS-or-SMS/m-p/40005#M2562" target="_blank"&gt;https://community.checkpoint.com/t5/API-CLI-Discussion/Disable-Delete-Rules-with-a-Zero-Hit-Count-MDS-or-SMS/m-p/40005#M2562&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2023 16:15:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194418#M36179</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-10-06T16:15:33Z</dc:date>
    </item>
    <item>
      <title>Re: Delete rules without traffic R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194422#M36180</link>
      <description>&lt;P&gt;Whats the command to show rules with 0 hits? I cant seem to find it in the API guide&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2023 16:24:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194422#M36180</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-06T16:24:50Z</dc:date>
    </item>
    <item>
      <title>Re: Delete rules without traffic R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194533#M36208</link>
      <description>&lt;P&gt;The API will only tell you how many hits a given Access Rule has gotten.&lt;BR /&gt;You can write a script (similar to what I pointed to) that pulls out the rules have zero hits.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 12:52:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194533#M36208</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-10-09T12:52:40Z</dc:date>
    </item>
    <item>
      <title>Re: Delete rules without traffic R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194535#M36209</link>
      <description>&lt;P&gt;Thats what I was trying to find in api guide, but could not. I searched for command that gives just the actual hits, but unable to locate one.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 13:15:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194535#M36209</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-09T13:15:07Z</dc:date>
    </item>
    <item>
      <title>Re: Delete rules without traffic R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194537#M36210</link>
      <description>&lt;P&gt;Hey &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;I highly disagree on this part &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; We have some 80.000 firewall rules across our install base,&lt;/P&gt;
&lt;P&gt;and have started a massive project cleaning up some +40.000 that is suspected unused.&lt;/P&gt;
&lt;P&gt;We have found it neccessary to query our log system for logs with uid for each unused rule found in Smart Console.&lt;/P&gt;
&lt;P&gt;We see around 1.000 rules that actually show logs in our log system (or smartlog) but hitcounter is 0.&lt;/P&gt;
&lt;P&gt;I am just warning you to not bulk delete rules. In critical environments, whis will quickly lead to incidents.&lt;/P&gt;
&lt;P&gt;I have spent many hours in the postgres db analyzing the design of the hit counter. (it's really bad) when we built all the logic behind the firewall cleaning&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;edit: we run r81.10 take NEW'ish - But I found this issue to be true on all versions. Not on r81.20 yet, but I see the db design is the same.&lt;/P&gt;
&lt;P&gt;/Henrik&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 13:33:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194537#M36210</guid>
      <dc:creator>Henrik_Noerr1</dc:creator>
      <dc:date>2023-10-09T13:33:20Z</dc:date>
    </item>
    <item>
      <title>Re: Delete rules without traffic R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194539#M36211</link>
      <description>&lt;P&gt;K, thats fair. Im just speaking from my extensive testing in the lab and production as well, it was accurate 100% of the time.&lt;/P&gt;
&lt;P&gt;But, everyone's experience is different, I suppose.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 13:34:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194539#M36211</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-09T13:34:20Z</dc:date>
    </item>
    <item>
      <title>Re: Delete rules without traffic R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194551#M36214</link>
      <description>&lt;P&gt;You can buy 3rd party firewall policy management tools that tell you 'last date hit' as well as how many hits.&lt;/P&gt;
&lt;P&gt;We found a rule for TACACS access that has not been used for 2 years. Doesn't mean we don't need it, just that nobody logged into a particular set of switches in the last 2 years, which is probably good news.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 16:31:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194551#M36214</guid>
      <dc:creator>Scott_Paisley</dc:creator>
      <dc:date>2023-10-09T16:31:31Z</dc:date>
    </item>
    <item>
      <title>Re: Delete rules without traffic R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194555#M36216</link>
      <description>&lt;P&gt;Good to know...any specific tool you use/like?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 18:49:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194555#M36216</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-09T18:49:26Z</dc:date>
    </item>
    <item>
      <title>Re: Delete rules without traffic R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194559#M36218</link>
      <description>&lt;P&gt;Tufin&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 18:52:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194559#M36218</guid>
      <dc:creator>Scott_Paisley</dc:creator>
      <dc:date>2023-10-09T18:52:41Z</dc:date>
    </item>
    <item>
      <title>Re: Delete rules without traffic R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194561#M36220</link>
      <description>&lt;P&gt;Never used it, but heard good things about it.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 18:56:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194561#M36220</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-09T18:56:05Z</dc:date>
    </item>
    <item>
      <title>Re: Delete rules without traffic R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194562#M36221</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;export RANGE_AGO="6 months"

export RANGE=$(echo ${RANGE_AGO}|sed 's/ //g')

export FROM_DATE=$(date -d "${RANGE_AGO} ago" +"%Y-%m-%d")

export TO_DATE=$(date +"%Y-%m-%d")

export MGMT_CLI_FORMAT=json



* MGMT_CLI locally on management server:

mgmt_cli show-access-rulebase name Network package Standard show-hits true hits-settings.from-date ${FROM_DATE} hits-settings.to-date ${TO_DATE}  use-object-dictionary false limit 350 &amp;gt; access_rules.last_${RANGE}.json



* REST API:  send this JSON body via 'curl' or whatever:

{ "name" : "Network",

 "show-hits" : true,

"hits-settings" : { "from-date" : "'${FROM_DATE}'", "to-date" : "'${TO_DATE}'" },

 "limit" : 350,

 "details-level" : "uid" }
&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 19:05:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194562#M36221</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2023-10-09T19:05:05Z</dc:date>
    </item>
    <item>
      <title>Re: Delete rules without traffic R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194631#M36239</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Just a note, while in my experience the Hits counter is correct, also think about when the rule was last modified. For example, if a rule was created yesterday, it's likely to not have any hits today.&lt;/P&gt;&lt;P&gt;So i usually take that into account when looking through the rulebase (manually) in order to disable unused rules. My rule of thumb is that a rule has not been used for a year and not been modified in this time either.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 08:58:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194631#M36239</guid>
      <dc:creator>SomAustrianCity</dc:creator>
      <dc:date>2023-10-10T08:58:46Z</dc:date>
    </item>
    <item>
      <title>Re: Delete rules without traffic R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194640#M36242</link>
      <description>&lt;P&gt;That makes sense, for sure. I can also say, again, from myown extensive testing, that in R81.20, hit count seems to be better than before, meaning, gets updated faster and I find is totally accurate.&lt;/P&gt;
&lt;P&gt;But again, as I said previously, everyone's experience varies.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 10:09:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194640#M36242</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-10T10:09:51Z</dc:date>
    </item>
    <item>
      <title>Re: Delete rules without traffic R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194690#M36252</link>
      <description>&lt;P&gt;I find that using the zero hits does not always paint a clear picture. What if the rule with zero hits is actually required, but there is another rule higher in the policy that is overly permissive? When I look at zero hit rules, I often will look for the source, destination, and service within the logs to determine if the traffic is allowed - or dropped - on a different rule. I then would review this other rule to determine if it is defined accurately, or if there is a need to modify it. If the other rule is defined correctly, but I need the zero hit rule for tracking purposes, then I will move the zero hit rule accordingly. Likewise, if the other rule is defined correctly, then I would delete the rule with zero hits.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I don't find the traffic in logs, now I can be a bit more assured the rule may not be needed. I still feel there needs to be some additional thought put into it though. Do you have an asset database? I would look up the owner of the asset and ask the question why is there a rule? Maybe it is something that only gets used in the event of an emergency - document that! Maybe it is an asset that has been decommissioned - what wasn't the firewall team notified? Is there a business process that is broken, or maybe needs to be defined?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think you can probably get the idea from here. Just because there are zero hits does not always mean the rule can be deleted. Most of the time it probably does, but always do your due diligence when you find these rules.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 15:56:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194690#M36252</guid>
      <dc:creator>CP_Chris</dc:creator>
      <dc:date>2023-10-10T15:56:16Z</dc:date>
    </item>
    <item>
      <title>Re: Delete rules without traffic R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194692#M36253</link>
      <description>&lt;P&gt;Those are all valid points, for sure.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 16:22:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194692#M36253</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-10T16:22:16Z</dc:date>
    </item>
    <item>
      <title>Re: Delete rules without traffic R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194700#M36254</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Is there a way to "export" in a report, all the rules that appear with "0 Hits" in our rule base?&lt;/P&gt;
&lt;P&gt;In such a way, that a manual analysis can be done, in order to make a better decision on whether or not these rules should be deleted.&lt;/P&gt;
&lt;P&gt;Greetings.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 17:33:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delete-rules-without-traffic-R81-10/m-p/194700#M36254</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-10-10T17:33:20Z</dc:date>
    </item>
  </channel>
</rss>

