<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: fw up_execute Equivalent for NAT Rule Matches? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-up-execute-Equivalent-for-NAT-Rule-Matches/m-p/102065#M8005</link>
    <description>&lt;P&gt;Haven’t seen and with NAT it’s a bit more complicated due to the fact some of the NAT isn’t handled by actual rules but rather as a result of object definition.&lt;/P&gt;</description>
    <pubDate>Sat, 14 Nov 2020 16:11:56 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-11-14T16:11:56Z</dc:date>
    <item>
      <title>fw up_execute Equivalent for NAT Rule Matches?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-up-execute-Equivalent-for-NAT-Rule-Matches/m-p/102060#M8003</link>
      <description>&lt;P&gt;&lt;STRONG&gt;fw up_execute&lt;/STRONG&gt; can be run on the gateway to find a matching Network policy rule in the live policy like this:&lt;/P&gt;
&lt;DIV id="tinyMceEditorTimothy_Hall_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="up_execute.png" style="width: 874px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8935i8C13FB0A4A42119D/image-size/large?v=v2&amp;amp;px=999" role="button" title="up_execute.png" alt="up_execute.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there an equivalent CLI utility to find a matching NAT policy rule on the live gateway?&amp;nbsp; I'm aware that Packet Mode searches can be executed against the NAT policy in the SmartConsole, but I'm looking for a CLI utility on the gateway itself.&amp;nbsp; Thanks!&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 14 Nov 2020 13:35:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-up-execute-Equivalent-for-NAT-Rule-Matches/m-p/102060#M8003</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-11-14T13:35:54Z</dc:date>
    </item>
    <item>
      <title>Re: fw up_execute Equivalent for NAT Rule Matches?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-up-execute-Equivalent-for-NAT-Rule-Matches/m-p/102065#M8005</link>
      <description>&lt;P&gt;Haven’t seen and with NAT it’s a bit more complicated due to the fact some of the NAT isn’t handled by actual rules but rather as a result of object definition.&lt;/P&gt;</description>
      <pubDate>Sat, 14 Nov 2020 16:11:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-up-execute-Equivalent-for-NAT-Rule-Matches/m-p/102065#M8005</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-11-14T16:11:56Z</dc:date>
    </item>
    <item>
      <title>Re: fw up_execute Equivalent for NAT Rule Matches?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-up-execute-Equivalent-for-NAT-Rule-Matches/m-p/102069#M8006</link>
      <description>&lt;P&gt;Not even in R81?&amp;nbsp; It seems like the NAT policy in that version is now acting more like a "real" policy layer, and allowing the use of Security Zones &amp;amp; Dynamic Objects including Access Roles, as well as keeping hit counts.&lt;/P&gt;</description>
      <pubDate>Sun, 15 Nov 2020 00:15:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-up-execute-Equivalent-for-NAT-Rule-Matches/m-p/102069#M8006</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-11-15T00:15:09Z</dc:date>
    </item>
    <item>
      <title>Re: fw up_execute Equivalent for NAT Rule Matches?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-up-execute-Equivalent-for-NAT-Rule-Matches/m-p/102101#M8007</link>
      <description>&lt;P&gt;Perhaps there's a hidden flag for fw up_execute?&lt;/P&gt;</description>
      <pubDate>Mon, 16 Nov 2020 04:52:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-up-execute-Equivalent-for-NAT-Rule-Matches/m-p/102101#M8007</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-11-16T04:52:27Z</dc:date>
    </item>
    <item>
      <title>Re: fw up_execute Equivalent for NAT Rule Matches?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-up-execute-Equivalent-for-NAT-Rule-Matches/m-p/170560#M30895</link>
      <description>&lt;P&gt;bump thread - this would be a useful feature&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2023 10:37:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-up-execute-Equivalent-for-NAT-Rule-Matches/m-p/170560#M30895</guid>
      <dc:creator>Richard_Carson</dc:creator>
      <dc:date>2023-02-07T10:37:54Z</dc:date>
    </item>
    <item>
      <title>Re: fw up_execute Equivalent for NAT Rule Matches?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-up-execute-Equivalent-for-NAT-Rule-Matches/m-p/170606#M30896</link>
      <description>&lt;P&gt;You can try searching the contents of the fwx_cache table which will hold the most recently hit NAT rules, see my post here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/NAT-Cache-Table-Full/m-p/53547/highlight/true#M10689" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/NAT-Cache-Table-Full/m-p/53547/highlight/true#M10689&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;here is another helpful tool as well:&lt;/P&gt;
&lt;H2&gt;&lt;FONT size="4"&gt;&lt;A id="link_25" title="showtable.sh - it shows statistics of the connections, fxw_cache and sam_blocked_ips tables" href="https://community.checkpoint.com/t5/API-CLI-Discussion/showtable-sh-it-shows-statistics-of-the-connections-fxw-cache/m-p/38974?search-action-id=58581607297&amp;amp;search-result-uid=38974" target="_self"&gt;showtable.sh - it shows statistics of the connecti...&lt;/A&gt;&lt;/FONT&gt;&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2023 15:11:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-up-execute-Equivalent-for-NAT-Rule-Matches/m-p/170606#M30896</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-02-07T15:11:59Z</dc:date>
    </item>
  </channel>
</rss>

