<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R82 cluster monitoring with Insights in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-cluster-monitoring-with-Insights/m-p/221589#M42435</link>
    <description>&lt;P&gt;Never mind, I googled it quick, ran this command and now I see the menu. let me check it later on.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[Expert@CP-EXL-1-s01-01:0]# stty cols 200 rows 150&lt;/P&gt;</description>
    <pubDate>Mon, 22 Jul 2024 15:09:05 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-07-22T15:09:05Z</dc:date>
    <item>
      <title>R82 cluster monitoring with Insights</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-cluster-monitoring-with-Insights/m-p/221553#M42426</link>
      <description>&lt;P&gt;Hi Checkmates,&lt;/P&gt;&lt;P&gt;I have created my own lab with 2x 23500 with R82 EA configured as ElasticXL cluster.&lt;BR /&gt;Everything looks fine except one minor thing... I don't see any traffic in Insights -&amp;gt; Tools -&amp;gt; ConnView:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="elxl1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26925i9E7FC128C7F9910F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="elxl1.png" alt="elxl1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;It doesn't matter if I use filter on the left to see particular traffic or not ... after I hit Search button - I see nothing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Of course there is a traffic from host in "net1" (internal) to host in "net2" (external) - it goes via Check Point R82 (NAT+routing_firewall). I can see this traffic via tcpdump/cppcap/fw monitor ... in logs, etc.&lt;/P&gt;&lt;P&gt;On the other hand - the same looks perfect in TechPoint's&amp;nbsp;Quantum R82 ElasticXL (EA Review):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="elxl2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26926i000E16320F5AF1F8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="elxl2.png" alt="elxl2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any requirement for this tool to be able to display connections ?&lt;BR /&gt;For example some process/daemon/etc. must be configured first ?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;BTW&lt;BR /&gt;R82 looks amazing, especially ElasticXL in my opinion will be game changer !&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;--&lt;BR /&gt;Best&lt;BR /&gt;Marcin&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 14:47:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-cluster-monitoring-with-Insights/m-p/221553#M42426</guid>
      <dc:creator>marcyn</dc:creator>
      <dc:date>2024-07-22T14:47:26Z</dc:date>
    </item>
    <item>
      <title>Re: R82 cluster monitoring with Insights</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-cluster-monitoring-with-Insights/m-p/221574#M42428</link>
      <description>&lt;P&gt;Hi Marcin,&lt;/P&gt;
&lt;P&gt;You are correct and you should see the connection table with or without filter.&lt;/P&gt;
&lt;P&gt;Unless your query exceeded max entries of 1000 on one of your cluster member. but in that case you should have seen pop up alert on insight mentioning this and tell you to narrow down your search by adding more filters.&lt;/P&gt;
&lt;P&gt;I will install EA version and see if reproduce.&lt;/P&gt;
&lt;P&gt;Will keep you updated.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Shai&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 14:10:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-cluster-monitoring-with-Insights/m-p/221574#M42428</guid>
      <dc:creator>ShaiF</dc:creator>
      <dc:date>2024-07-22T14:10:14Z</dc:date>
    </item>
    <item>
      <title>Re: R82 cluster monitoring with Insights</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-cluster-monitoring-with-Insights/m-p/221578#M42430</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/33955"&gt;@ShaiF&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Great, looking forward your test results.&lt;/P&gt;&lt;P&gt;Just to clarify - my lab is absolutely basic one ... I've just addressed two interfaces, added this cluster to SMS, changed CleanUp Rule to become PassAll, started the traffic flow ... and generally that's it.&lt;BR /&gt;Insights works great - I see a lt of statistics (first pane), alerts, etc ... only the last pane "doesn't like me" &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Hopefully we will find why.&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt;Best&lt;BR /&gt;Marcin&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 14:17:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-cluster-monitoring-with-Insights/m-p/221578#M42430</guid>
      <dc:creator>marcyn</dc:creator>
      <dc:date>2024-07-22T14:17:58Z</dc:date>
    </item>
    <item>
      <title>Re: R82 cluster monitoring with Insights</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-cluster-monitoring-with-Insights/m-p/221579#M42431</link>
      <description>&lt;P&gt;Hey Marcin,&lt;/P&gt;
&lt;P&gt;Is this cpview or something else? I have exl lab, so can check as well.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 14:22:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-cluster-monitoring-with-Insights/m-p/221579#M42431</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-22T14:22:30Z</dc:date>
    </item>
    <item>
      <title>Re: R82 cluster monitoring with Insights</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-cluster-monitoring-with-Insights/m-p/221582#M42432</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;This is new tool introduced in R82 for cluster monitoring (for ElasticXL and Maestro).&lt;/P&gt;&lt;P&gt;You can run it by executing command "insights" from gateway.&lt;/P&gt;&lt;P&gt;You will love this tool &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt;Best&lt;BR /&gt;Marcin&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 14:34:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-cluster-monitoring-with-Insights/m-p/221582#M42432</guid>
      <dc:creator>marcyn</dc:creator>
      <dc:date>2024-07-22T14:34:38Z</dc:date>
    </item>
    <item>
      <title>Re: R82 cluster monitoring with Insights</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-cluster-monitoring-with-Insights/m-p/221584#M42433</link>
      <description>&lt;P&gt;I used eve-ng for this, gives below...will see if that setting is in terminal settings, cant seem to find it lol&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;[Expert@CP-EXL-1-s01-01:0]# insights&lt;/P&gt;
&lt;P&gt;Insights is supported only on terminals with settings of at least 190 columns and 25 rows.&lt;BR /&gt;Current terminal size is (columns = 72, rows = 19)&lt;BR /&gt;To watch information regarding your cluster use one of the following commands:&lt;BR /&gt;- From gClish:&lt;BR /&gt;&amp;gt; show cluster info ...&lt;BR /&gt;- From expert:&lt;BR /&gt;# cinfo --help&lt;/P&gt;
&lt;P&gt;For best view of insights adjust your preferred terminal application with the following settings:&lt;BR /&gt;- Terminal type: xterm&lt;BR /&gt;- Font: consolas&lt;BR /&gt;- Encoding: UTF-8&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;[Expert@CP-EXL-1-s01-01:0]#&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 14:55:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-cluster-monitoring-with-Insights/m-p/221584#M42433</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-22T14:55:31Z</dc:date>
    </item>
    <item>
      <title>Re: R82 cluster monitoring with Insights</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-cluster-monitoring-with-Insights/m-p/221585#M42434</link>
      <description>&lt;P&gt;just enlarge your terminal window to fulfill this requirement:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Insights is supported only on terminals with settings of at least 190 columns and 25 rows.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;As you can see yours is like this:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Current terminal size is (columns = 72, rows = 19)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And then magic will happen &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;m.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 14:44:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-cluster-monitoring-with-Insights/m-p/221585#M42434</guid>
      <dc:creator>marcyn</dc:creator>
      <dc:date>2024-07-22T14:44:00Z</dc:date>
    </item>
    <item>
      <title>Re: R82 cluster monitoring with Insights</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-cluster-monitoring-with-Insights/m-p/221589#M42435</link>
      <description>&lt;P&gt;Never mind, I googled it quick, ran this command and now I see the menu. let me check it later on.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[Expert@CP-EXL-1-s01-01:0]# stty cols 200 rows 150&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 15:09:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-cluster-monitoring-with-Insights/m-p/221589#M42435</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-22T15:09:05Z</dc:date>
    </item>
    <item>
      <title>Re: R82 cluster monitoring with Insights</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-cluster-monitoring-with-Insights/m-p/221664#M42441</link>
      <description>&lt;P&gt;&lt;SPAN&gt;After investigating the issue. We found out it is due to the fact connview tool (which insights ConnView tab is using) is not working with Kernel FW mode.&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Solution is to change USFW.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 08:14:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-cluster-monitoring-with-Insights/m-p/221664#M42441</guid>
      <dc:creator>ShaiF</dc:creator>
      <dc:date>2024-07-23T08:14:01Z</dc:date>
    </item>
    <item>
      <title>Re: R82 cluster monitoring with Insights</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-cluster-monitoring-with-Insights/m-p/221665#M42442</link>
      <description>&lt;P&gt;Yes,&lt;/P&gt;&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/33955"&gt;@ShaiF&lt;/a&gt;&amp;nbsp;for this quick remote session.&lt;/P&gt;&lt;P&gt;And I can confirm what Shai just wrote.&lt;BR /&gt;We found out this:&lt;BR /&gt;&lt;BR /&gt;[Expert@R82-01-s01-01:0]# connview&lt;BR /&gt;[Error] ConnView is not supported on a Security Gateway that runs the Firewall in the Kernel mode (KSFW). For more information, see sk167052.&lt;/P&gt;&lt;P&gt;And everything is clear now ... It is really "funny" because USFW as we know is enabled by default, but not for 23500 appliance ... which I have in my lab &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;/it looks like only this one particular model does not have it enabled by default ... lucky me &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; /&lt;/P&gt;&lt;P&gt;After I switched to USFW I can see connections in insights.&lt;BR /&gt;So in case anybody else will have such "issue" it's just Firewall Mode.&lt;/P&gt;&lt;P&gt;Thank you Shai, it was resolved really fast &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt;Best&lt;BR /&gt;m.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 08:28:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-cluster-monitoring-with-Insights/m-p/221665#M42442</guid>
      <dc:creator>marcyn</dc:creator>
      <dc:date>2024-07-23T08:28:04Z</dc:date>
    </item>
    <item>
      <title>Re: R82 cluster monitoring with Insights</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-cluster-monitoring-with-Insights/m-p/221667#M42443</link>
      <description>&lt;P&gt;EDITED: My original statement was incorrect, now removed.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/33955"&gt;@ShaiF&lt;/a&gt;&amp;nbsp;knows better &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 10:31:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-cluster-monitoring-with-Insights/m-p/221667#M42443</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-07-23T10:31:08Z</dc:date>
    </item>
    <item>
      <title>Re: R82 cluster monitoring with Insights</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-cluster-monitoring-with-Insights/m-p/221668#M42444</link>
      <description>&lt;P&gt;Hi Val,&lt;/P&gt;
&lt;P&gt;In EA take FW mode depends on models and platform (EXL run USFW by default as well on some models and VM). In GA take all appliances and platforms (Single Gateway, ClusterXL, Maestro, EXL..) will have USFW by default.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Shai.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 09:53:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-cluster-monitoring-with-Insights/m-p/221668#M42444</guid>
      <dc:creator>ShaiF</dc:creator>
      <dc:date>2024-07-23T09:53:36Z</dc:date>
    </item>
    <item>
      <title>Re: R82 cluster monitoring with Insights</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-cluster-monitoring-with-Insights/m-p/221676#M42448</link>
      <description>&lt;P&gt;Will check this in the lab later &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 11:21:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-cluster-monitoring-with-Insights/m-p/221676#M42448</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-23T11:21:00Z</dc:date>
    </item>
    <item>
      <title>Re: R82 cluster monitoring with Insights</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-cluster-monitoring-with-Insights/m-p/221684#M42454</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/33955"&gt;@ShaiF&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/78158"&gt;@marcyn&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just for context, I tested it in elasticxl in eve-ng and shows user kernel mode is enabled.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;elasticxl:&lt;/P&gt;
&lt;P&gt;[Expert@CP-EXL-1-s01-01:0]# cpprod_util FwIsUsermode&lt;BR /&gt;1&lt;BR /&gt;[Expert@CP-EXL-1-s01-01:0]#&lt;/P&gt;
&lt;P&gt;regular R82:&lt;/P&gt;
&lt;P&gt;[Expert@R82-TEST-FW:0]# cpprod_util FwIsUsermode&lt;BR /&gt;1&lt;BR /&gt;[Expert@R82-TEST-FW:0]#&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 12:00:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-cluster-monitoring-with-Insights/m-p/221684#M42454</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-23T12:00:52Z</dc:date>
    </item>
  </channel>
</rss>

