<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic show rule-hits with duplicated id rules in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/show-rule-hits-with-duplicated-id-rules/m-p/81732#M3412</link>
    <description>&lt;P&gt;Hi everyone. I've SMB 1490 appliance with r77.20,87 Build 966.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I run&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" color="#000080"&gt;my.firewall&amp;gt; show rule-hits&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;I get&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Top Rule Hits&lt;BR /&gt;-------------&lt;BR /&gt;Rule Number Rule Hits&lt;BR /&gt;13 332620&lt;BR /&gt;6 283579&lt;BR /&gt;13 220694&lt;BR /&gt;6 69117&lt;BR /&gt;6 68935&lt;BR /&gt;13 65383&lt;BR /&gt;13 59987&lt;BR /&gt;6 50980&lt;BR /&gt;18 30623&lt;BR /&gt;5 26940&lt;BR /&gt;18 15382&lt;BR /&gt;5 13210&lt;BR /&gt;15 13197&lt;BR /&gt;15 10944&lt;BR /&gt;0 5905&lt;BR /&gt;0 5892&lt;BR /&gt;.....&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Why do rules id appear more than once? (13, 6, 18, 15, 0 ...)&lt;BR /&gt;Why does rule 0 appear? What does this rule id refer to?&lt;/P&gt;</description>
    <pubDate>Tue, 14 Apr 2020 05:40:33 GMT</pubDate>
    <dc:creator>LuisSP</dc:creator>
    <dc:date>2020-04-14T05:40:33Z</dc:date>
    <item>
      <title>show rule-hits with duplicated id rules</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/show-rule-hits-with-duplicated-id-rules/m-p/81732#M3412</link>
      <description>&lt;P&gt;Hi everyone. I've SMB 1490 appliance with r77.20,87 Build 966.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I run&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" color="#000080"&gt;my.firewall&amp;gt; show rule-hits&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;I get&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Top Rule Hits&lt;BR /&gt;-------------&lt;BR /&gt;Rule Number Rule Hits&lt;BR /&gt;13 332620&lt;BR /&gt;6 283579&lt;BR /&gt;13 220694&lt;BR /&gt;6 69117&lt;BR /&gt;6 68935&lt;BR /&gt;13 65383&lt;BR /&gt;13 59987&lt;BR /&gt;6 50980&lt;BR /&gt;18 30623&lt;BR /&gt;5 26940&lt;BR /&gt;18 15382&lt;BR /&gt;5 13210&lt;BR /&gt;15 13197&lt;BR /&gt;15 10944&lt;BR /&gt;0 5905&lt;BR /&gt;0 5892&lt;BR /&gt;.....&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Why do rules id appear more than once? (13, 6, 18, 15, 0 ...)&lt;BR /&gt;Why does rule 0 appear? What does this rule id refer to?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2020 05:40:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/show-rule-hits-with-duplicated-id-rules/m-p/81732#M3412</guid>
      <dc:creator>LuisSP</dc:creator>
      <dc:date>2020-04-14T05:40:33Z</dc:date>
    </item>
    <item>
      <title>Re: show rule-hits with duplicated id rules</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/show-rule-hits-with-duplicated-id-rules/m-p/81734#M3413</link>
      <description>&lt;P&gt;Sorry, no inline on SMB&lt;/P&gt;
&lt;P&gt;Is this unit locally or centrally managed?&lt;BR /&gt;Rule number 0 is for implied rules.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2020 06:27:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/show-rule-hits-with-duplicated-id-rules/m-p/81734#M3413</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-04-14T06:27:56Z</dc:date>
    </item>
    <item>
      <title>Re: show rule-hits with duplicated id rules</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/show-rule-hits-with-duplicated-id-rules/m-p/81737#M3414</link>
      <description>Thaks for you reply, but I don't have inline layers. It's SMB 1490 locally managed without capacity to such layers.&lt;BR /&gt;&lt;BR /&gt;Concern rule number 0, how do I can to know what implied rules (configuration) is matching for?</description>
      <pubDate>Tue, 14 Apr 2020 06:31:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/show-rule-hits-with-duplicated-id-rules/m-p/81737#M3414</guid>
      <dc:creator>LuisSP</dc:creator>
      <dc:date>2020-04-14T06:31:41Z</dc:date>
    </item>
    <item>
      <title>Re: show rule-hits with duplicated id rules</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/show-rule-hits-with-duplicated-id-rules/m-p/81856#M3417</link>
      <description>The rule 0 hits are most probably the hits for management ports (however you normally would not see these in logs) and also things like VPN setup and authentication. Things that are allowed but does not have a rule for it.</description>
      <pubDate>Tue, 14 Apr 2020 20:50:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/show-rule-hits-with-duplicated-id-rules/m-p/81856#M3417</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-04-14T20:50:20Z</dc:date>
    </item>
    <item>
      <title>Re: show rule-hits with duplicated id rules</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/show-rule-hits-with-duplicated-id-rules/m-p/81877#M3420</link>
      <description>From what I've been able to see in TAC cases, multiple instances of a rule may refer to the different rulebases in SMB (inbound versus outbound).&lt;BR /&gt;Unfortunately, the platform doesn't provide a way to differentiate the hit counts currently.</description>
      <pubDate>Tue, 14 Apr 2020 22:27:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/show-rule-hits-with-duplicated-id-rules/m-p/81877#M3420</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-04-14T22:27:23Z</dc:date>
    </item>
    <item>
      <title>Re: show rule-hits with duplicated id rules</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/show-rule-hits-with-duplicated-id-rules/m-p/82047#M3428</link>
      <description>&lt;P&gt;Well, in fact some rules appear 4 times. It is unfortunate that I cannot have the visibility in this regard, to improve the order of the rules and with it the performance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I appreciate your comments, thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2020 20:01:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/show-rule-hits-with-duplicated-id-rules/m-p/82047#M3428</guid>
      <dc:creator>LuisSP</dc:creator>
      <dc:date>2020-04-15T20:01:26Z</dc:date>
    </item>
  </channel>
</rss>

