<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: fw ctl conntab output in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/fw-ctl-conntab-output/m-p/62321#M12646</link>
    <description>Connections that are starting/ending have much shorter timeouts.&lt;BR /&gt;In this case, this starting connection has a timeout of 25 seconds.&lt;BR /&gt;The 23 refers to the number of seconds the connection has left before it is timed out.</description>
    <pubDate>Mon, 09 Sep 2019 19:49:36 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2019-09-09T19:49:36Z</dc:date>
    <item>
      <title>fw ctl conntab output</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fw-ctl-conntab-output/m-p/62246#M12633</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I run this command on my firewall R80.10&lt;/P&gt;&lt;P&gt;fw ctl conntab&amp;nbsp; -dip=10.168.39.31 -sip=10.168.75.11&amp;nbsp;&lt;/P&gt;&lt;P&gt;And I saw the result :&lt;/P&gt;&lt;P&gt;&amp;lt;(inbound, src=[10.168.75.11,39125], dest=[10.168.39.31,5701], TCP); &lt;STRONG&gt;23/25&lt;/STRONG&gt;, rule=24, tcp state=&lt;STRONG&gt;SYN_SENT&lt;/STRONG&gt;, service=343, conn modules: PSL, SeqVerifier&amp;gt;&lt;/P&gt;&lt;P&gt;The "tcp state" is&amp;nbsp;SYN_SENT -&amp;gt; Does this mean the connection is not established because 3-step is not finished? If so, why this "not-established-connection" is still in connection table?&lt;/P&gt;&lt;P&gt;What is mean of 23/25? -&amp;gt; Does this mean "after 23s" this connection will be removed?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks very much for replying me!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Dec 2021 04:29:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fw-ctl-conntab-output/m-p/62246#M12633</guid>
      <dc:creator>minhhaivietnam</dc:creator>
      <dc:date>2021-12-02T04:29:20Z</dc:date>
    </item>
    <item>
      <title>Re: fw ctl conntab output</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fw-ctl-conntab-output/m-p/62321#M12646</link>
      <description>Connections that are starting/ending have much shorter timeouts.&lt;BR /&gt;In this case, this starting connection has a timeout of 25 seconds.&lt;BR /&gt;The 23 refers to the number of seconds the connection has left before it is timed out.</description>
      <pubDate>Mon, 09 Sep 2019 19:49:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fw-ctl-conntab-output/m-p/62321#M12646</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-09-09T19:49:36Z</dc:date>
    </item>
    <item>
      <title>Re: fw ctl conntab output</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fw-ctl-conntab-output/m-p/118550#M22047</link>
      <description>&lt;P&gt;can you please help to understand below connection, how much old in hrs&lt;/P&gt;&lt;P&gt;&amp;lt;(inbound, src=[sip,27807], dest=[dip,7005], TCP); &lt;STRONG&gt;3522/3604&lt;/STRONG&gt;, rule=3468, tcp state=TCP_ESTABLISHED, service=2233, Ifncin=46, Ifnsin=28, conn modules: Authentication, FG-1&amp;gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 May 2021 15:38:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fw-ctl-conntab-output/m-p/118550#M22047</guid>
      <dc:creator>maheshgirnare</dc:creator>
      <dc:date>2021-05-17T15:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: fw ctl conntab output</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fw-ctl-conntab-output/m-p/118581#M22060</link>
      <description>&lt;P&gt;I believe simple math there would 3600 seconds is 60 minutes, so 3522 would be 58 minutes and 42 seconds if my math is right : )&lt;/P&gt;</description>
      <pubDate>Tue, 18 May 2021 00:36:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fw-ctl-conntab-output/m-p/118581#M22060</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-05-18T00:36:31Z</dc:date>
    </item>
    <item>
      <title>Re: fw ctl conntab output</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fw-ctl-conntab-output/m-p/118585#M22062</link>
      <description>&lt;P&gt;That doesn't tell you how long the connection has been active, only that the entry in the connection table expires in that time.&lt;BR /&gt;We don't track how long the connection has been active in the state tables.&lt;/P&gt;</description>
      <pubDate>Tue, 18 May 2021 01:45:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fw-ctl-conntab-output/m-p/118585#M22062</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-05-18T01:45:08Z</dc:date>
    </item>
    <item>
      <title>Re: fw ctl conntab output</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fw-ctl-conntab-output/m-p/118586#M22063</link>
      <description>&lt;P&gt;Generally the state table does not track this kind of information as Phoneboy said, however there is an exception to this if "Accounting" is enabled in the Track column of the matching rule.&amp;nbsp; As a result every 10 minutes or when the connection ends (whichever is sooner), extra logging information is sent indicating various accounting statistics about the connection that will appear in the SmartConsole log card for the connection.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However in the meantime the firewall is tracking numerous bits of extra information right in the "connections" state table including how long the connection has been active, in/out bytes, when a packet associated with the connection was last seen, etc.&amp;nbsp; Here is an example state table entry matching a rule that has Accounting enabled, the related fields are highlighted in red:&lt;/P&gt;
&lt;P&gt;20:43:51 5 N/A N/A 192.0.2.100 &amp;gt; N/A LogId: &amp;lt;max_null&amp;gt;; ContextNum: &amp;lt;max_null&amp;gt;; OriginSicName: &amp;lt;max_null&amp;gt;; : -----------------------------------(+); Direction: 0; Source: 192.0.2.1; SPort: 60738; Dest: 192.0.2.100; DPort: 22; Protocol: tcp; CPTFMT_sep: ;; Type: 114689; Rule: 1; Timeout: 507; Handler: 0; Ifncin: 1; Ifncout: 1; Ifnsin: -1; Ifnsout: -1; Bits: 0200e8000007c800; &lt;FONT color="#FF0000"&gt;ACT_Starttime: 17May2021 20:41:31; ACT_Segtime: 17May2021 20:41:31; ACT_Lastseen: 17May2021 20:43:51; ACT_Cliinpack: 537; ACT_Clioutpack: 0; ACT_Srvinpack: 618; ACT_Srvoutpack: 0; ACT_Cliinbyte: 0; ACT_Clioutbyte: 0; ACT_Srvinbyte: 0; ACT_Srvoutbyte: 0;&lt;/FONT&gt; Expires: 3598/3600; LastUpdateTime: 17May2021 20:43:51; ProductName: VPN-1 &amp;amp; FireWall-1; ProductFamily: Network;&lt;/P&gt;
&lt;P&gt;SecureXL/sim can also track accounting information, so utilizing Accounting does not affect acceleration status of the connection.&lt;/P&gt;</description>
      <pubDate>Tue, 18 May 2021 02:53:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fw-ctl-conntab-output/m-p/118586#M22063</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-05-18T02:53:43Z</dc:date>
    </item>
  </channel>
</rss>

