<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic delete unused NAT rules in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/delete-unused-NAT-rules/m-p/98566#M19253</link>
    <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;I have over 4000 of NAT rules, and I want to purge the unused ones. (there are a lot of legacy rules)&lt;BR /&gt;I know there is no hit count on them, this feature will be implemented in R81.&lt;BR /&gt;Do you have any proposals, ideas etc to this quickly or remains the old solution: check all of them manually .&lt;BR /&gt;I want avoid of mistakes, because it can cause service distruptions.&lt;/P&gt;&lt;P&gt;version: MGMT:R80.40, GW:R80.30&lt;/P&gt;&lt;P&gt;Looking forward to your answers,&lt;/P&gt;&lt;P&gt;Akos&lt;/P&gt;</description>
    <pubDate>Thu, 08 Oct 2020 15:20:43 GMT</pubDate>
    <dc:creator>AkosBakos</dc:creator>
    <dc:date>2020-10-08T15:20:43Z</dc:date>
    <item>
      <title>delete unused NAT rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/delete-unused-NAT-rules/m-p/98566#M19253</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;I have over 4000 of NAT rules, and I want to purge the unused ones. (there are a lot of legacy rules)&lt;BR /&gt;I know there is no hit count on them, this feature will be implemented in R81.&lt;BR /&gt;Do you have any proposals, ideas etc to this quickly or remains the old solution: check all of them manually .&lt;BR /&gt;I want avoid of mistakes, because it can cause service distruptions.&lt;/P&gt;&lt;P&gt;version: MGMT:R80.40, GW:R80.30&lt;/P&gt;&lt;P&gt;Looking forward to your answers,&lt;/P&gt;&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 15:20:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/delete-unused-NAT-rules/m-p/98566#M19253</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2020-10-08T15:20:43Z</dc:date>
    </item>
    <item>
      <title>Re: delete unused NAT rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/delete-unused-NAT-rules/m-p/98571#M19254</link>
      <description>&lt;P&gt;Just throwing out an option I may try... depending on the volume of data , you can setup a free Splunk server (I believe the free version of Splunk is 500M of data a day), or ELK, forward your logs there. You can write a query and see which ones are being hit.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 15:55:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/delete-unused-NAT-rules/m-p/98571#M19254</guid>
      <dc:creator>Mike_A</dc:creator>
      <dc:date>2020-10-08T15:55:59Z</dc:date>
    </item>
    <item>
      <title>Re: delete unused NAT rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/delete-unused-NAT-rules/m-p/98582#M19256</link>
      <description>&lt;P&gt;Really, your only option is to look at what’s been logged.&lt;BR /&gt;A third party SIEM might be helpful here but even without that, you might be able to process the logs and see what rule(s) are logged or not.&lt;BR /&gt;Its not foolproof of course, but it’s really the only piece of data you have to work with.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 17:16:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/delete-unused-NAT-rules/m-p/98582#M19256</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-10-08T17:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: delete unused NAT rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/delete-unused-NAT-rules/m-p/98599#M19258</link>
      <description>&lt;P&gt;Or wait for the hitcounters on NAT rules in R81.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 20:44:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/delete-unused-NAT-rules/m-p/98599#M19258</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-10-08T20:44:50Z</dc:date>
    </item>
    <item>
      <title>Re: delete unused NAT rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/delete-unused-NAT-rules/m-p/98823#M19276</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;Last night I dreamed from this scenario :-):&lt;/P&gt;&lt;P&gt;We are Check Point partner, and we can download the R81 EA.&lt;/P&gt;&lt;P&gt;If we install SmartCenter on R81 version, and we migrating the rulebase into, will we able to send the logs with #log exporter from the R80.40 log server?&lt;/P&gt;&lt;P&gt;I could work?&amp;nbsp; Or is it a blind track?&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Looking forward to your answer,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Akos&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2020 07:50:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/delete-unused-NAT-rules/m-p/98823#M19276</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2020-10-12T07:50:21Z</dc:date>
    </item>
    <item>
      <title>Re: delete unused NAT rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/delete-unused-NAT-rules/m-p/98896#M19278</link>
      <description>&lt;P&gt;Correct me if I';m wrong but to my knowledge the hitcounter is not filled from the logs on management but directly by the gateway.&lt;/P&gt;
&lt;P&gt;Therefore this scenario would not really work. Possibly Tufin or Algosec is able to do it that way.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2020 14:42:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/delete-unused-NAT-rules/m-p/98896#M19278</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-10-12T14:42:33Z</dc:date>
    </item>
  </channel>
</rss>

