<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Adding an entry to the connections table in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Adding-an-entry-to-the-connections-table/m-p/220524#M36752</link>
    <description>&lt;P&gt;Hi all!&lt;/P&gt;&lt;P&gt;In the R81.20 CLI Reference Guide, under fw tab section it shows this:&lt;/P&gt;&lt;TABLE width="933px" cellspacing="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="119.922px"&gt;&lt;P&gt;-a -e "&amp;lt;&lt;EM&gt;Entry&lt;/EM&gt;&amp;gt;"&lt;/P&gt;&lt;/TD&gt;&lt;TD width="812.078px"&gt;&lt;P&gt;Adds the specified entry to the specified kernel&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;tab&lt;/SPAN&gt;le.&lt;/P&gt;&lt;P&gt;If a kernel&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;tab&lt;/SPAN&gt;le has the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;expire&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;attribute, when you add an entry with the "-a -e &amp;lt;&lt;EM&gt;Entry&lt;/EM&gt;&amp;gt;" parameter, the new entry gets the default&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;tab&lt;/SPAN&gt;le timeout.&lt;/P&gt;&lt;P&gt;You can use this parameter only on the local&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Security Gateway&lt;/SPAN&gt;.&lt;/P&gt;&lt;TABLE cellspacing="0"&gt;&lt;COLGROUP&gt;&lt;COL /&gt;&lt;COL /&gt;&lt;/COLGROUP&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kamilazat_0-1720788416034.png" style="width: 25px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26752i6C0B2E4CF2A111A1/image-dimensions/25x25?v=v2" width="25" height="25" role="button" title="kamilazat_0-1720788416034.png" alt="kamilazat_0-1720788416034.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN class=""&gt;Warning&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- If you add a wrong entry, you can make your&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Security Gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;unresponsive.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried adding an entry in different formats in my lab, but every time the gateway became unresponsive (as warned). Now I have questions:&lt;/P&gt;&lt;P&gt;1. What is the 'right' entry that will not render the GW unresponsive? I used the 5-tuple format as stated in&amp;nbsp;sk65133 to no avail.&lt;/P&gt;&lt;P&gt;2. Does connections table have an expire attribute? If yes where can I learn more about it?&lt;/P&gt;&lt;P&gt;Thanks as always!&lt;/P&gt;</description>
    <pubDate>Fri, 12 Jul 2024 12:53:09 GMT</pubDate>
    <dc:creator>kamilazat</dc:creator>
    <dc:date>2024-07-12T12:53:09Z</dc:date>
    <item>
      <title>Adding an entry to the connections table</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Adding-an-entry-to-the-connections-table/m-p/220524#M36752</link>
      <description>&lt;P&gt;Hi all!&lt;/P&gt;&lt;P&gt;In the R81.20 CLI Reference Guide, under fw tab section it shows this:&lt;/P&gt;&lt;TABLE width="933px" cellspacing="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="119.922px"&gt;&lt;P&gt;-a -e "&amp;lt;&lt;EM&gt;Entry&lt;/EM&gt;&amp;gt;"&lt;/P&gt;&lt;/TD&gt;&lt;TD width="812.078px"&gt;&lt;P&gt;Adds the specified entry to the specified kernel&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;tab&lt;/SPAN&gt;le.&lt;/P&gt;&lt;P&gt;If a kernel&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;tab&lt;/SPAN&gt;le has the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;expire&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;attribute, when you add an entry with the "-a -e &amp;lt;&lt;EM&gt;Entry&lt;/EM&gt;&amp;gt;" parameter, the new entry gets the default&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;tab&lt;/SPAN&gt;le timeout.&lt;/P&gt;&lt;P&gt;You can use this parameter only on the local&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Security Gateway&lt;/SPAN&gt;.&lt;/P&gt;&lt;TABLE cellspacing="0"&gt;&lt;COLGROUP&gt;&lt;COL /&gt;&lt;COL /&gt;&lt;/COLGROUP&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kamilazat_0-1720788416034.png" style="width: 25px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26752i6C0B2E4CF2A111A1/image-dimensions/25x25?v=v2" width="25" height="25" role="button" title="kamilazat_0-1720788416034.png" alt="kamilazat_0-1720788416034.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN class=""&gt;Warning&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- If you add a wrong entry, you can make your&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Security Gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;unresponsive.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried adding an entry in different formats in my lab, but every time the gateway became unresponsive (as warned). Now I have questions:&lt;/P&gt;&lt;P&gt;1. What is the 'right' entry that will not render the GW unresponsive? I used the 5-tuple format as stated in&amp;nbsp;sk65133 to no avail.&lt;/P&gt;&lt;P&gt;2. Does connections table have an expire attribute? If yes where can I learn more about it?&lt;/P&gt;&lt;P&gt;Thanks as always!&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2024 12:53:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Adding-an-entry-to-the-connections-table/m-p/220524#M36752</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2024-07-12T12:53:09Z</dc:date>
    </item>
    <item>
      <title>Re: Adding an entry to the connections table</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Adding-an-entry-to-the-connections-table/m-p/220527#M36753</link>
      <description>&lt;P&gt;Can you send an example you used? Happy to try in my lab.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2024 13:18:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Adding-an-entry-to-the-connections-table/m-p/220527#M36753</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-12T13:18:51Z</dc:date>
    </item>
    <item>
      <title>Re: Adding an entry to the connections table</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Adding-an-entry-to-the-connections-table/m-p/220594#M36759</link>
      <description>&lt;P&gt;An exact example of what you tried would be helpful.&lt;BR /&gt;Having said that, adding or removing connection table entries from a live gateway is dangerous at best and not recommend.&lt;BR /&gt;Can you provide more details around WHY you are attempting to do this?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2024 18:52:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Adding-an-entry-to-the-connections-table/m-p/220594#M36759</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-12T18:52:05Z</dc:date>
    </item>
    <item>
      <title>Re: Adding an entry to the connections table</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Adding-an-entry-to-the-connections-table/m-p/220724#M36774</link>
      <description>&lt;P&gt;Thank you for the inquiries.&lt;/P&gt;&lt;P&gt;I found out that it was possible while looking up potential solutions to "resurrecting" a connection back into connections table (as mentioned by Tim Hall in this &lt;A href="https://community.checkpoint.com/t5/General-Topics/TCP-packet-out-of-state-First-packet-isn-t-SYN-tcp-flags-SYN-ACK/m-p/37166#M7876" target="_self"&gt;post&lt;/A&gt;) for a customer. I found out in the documentation that it actually is possible to add an entry to kernel tables. So I started playing in my dummy lab.&amp;nbsp;&lt;BR /&gt;What I tried is to blindly add a connection entry using the 5-tuple format (from&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk65133" target="_self"&gt;sk65133&lt;/A&gt;). And, of course, it rendered the gateway unresponsive and I had to revert to the previous snapshot.&lt;/P&gt;&lt;P&gt;We have opened a TAC case to troubleshoot the issue at hand. But since I started playing with connections table in a completely destroyable lab, I wanted to learn more about how it works and the reasons I'm failing in this. Maybe manually adding an entry is not possible in terms of connections table?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 07:09:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Adding-an-entry-to-the-connections-table/m-p/220724#M36774</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2024-07-15T07:09:19Z</dc:date>
    </item>
    <item>
      <title>Re: Adding an entry to the connections table</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Adding-an-entry-to-the-connections-table/m-p/220827#M36791</link>
      <description>&lt;P&gt;Note that a given connection flowing through the gateway can have FOUR entries, particularly if NAT is involved.&lt;BR /&gt;There are entries in other tables that may need to be added/modified as well.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 18:08:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Adding-an-entry-to-the-connections-table/m-p/220827#M36791</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-15T18:08:16Z</dc:date>
    </item>
    <item>
      <title>Re: Adding an entry to the connections table</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Adding-an-entry-to-the-connections-table/m-p/220894#M36802</link>
      <description>&lt;P&gt;I see, thank you very much for your answer. NAT is involved in that lab. So if I wanted to add an entry to connections table, I would have to simultaneously add entries to other tables, such as&amp;nbsp;fwx_alloc_global, fwx_cache etc.&lt;/P&gt;&lt;P&gt;Is there a resource I can study the details of these tables, like I can for connections table?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jul 2024 07:08:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Adding-an-entry-to-the-connections-table/m-p/220894#M36802</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2024-07-16T07:08:28Z</dc:date>
    </item>
    <item>
      <title>Re: Adding an entry to the connections table</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Adding-an-entry-to-the-connections-table/m-p/220972#M36816</link>
      <description>&lt;P&gt;Not that I’m aware of, unfortunately.&lt;BR /&gt;Some of these tables have changed with versions.&lt;/P&gt;
&lt;P&gt;If this is something that happens with a specific connection regularly, you might want to exempt it from state checking instead.&lt;BR /&gt;This way, you don’t have to manually try and patch it into the connections table(s).&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk11088" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk11088&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jul 2024 13:52:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Adding-an-entry-to-the-connections-table/m-p/220972#M36816</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-16T13:52:18Z</dc:date>
    </item>
  </channel>
</rss>

