cancel
Showing results for 
Search instead for 
Did you mean: 
Post a Question

CLI command to show FW/IPS Policy

What cli command to show all installed policy and also ips policy. 

Tags (1)
7 Replies
XBensemhoun
Silver

Re: CLI command to show FW/IPS Policy

Hi, you can use

cpstat fw

in order to find what policy package is installed on a Security Gateway.

For IPS, you'll have to use

ips stat

in order to check the ips status (active profile, update version, ...)

You can find such commands and lot more in the specific Admin Guide or on the CLI Reference Guide

Re: CLI command to show FW/IPS Policy

I mean, show/list all the firewall policy not the install policy package

0 Kudos
Danny
Pearl

Re: CLI command to show FW/IPS Policy

You want to see all the rules that are installed on the local gateway, right? This is possible starting from R80.10. https://community.checkpoint.com/people/dwelccfe6e688-522c-305c-adaa-194bd7a7becc mentioned the file that contains all the rules a while ago. Let me check and get back to your shortly.

0 Kudos
Admin
Admin

Re: CLI command to show FW/IPS Policy

I don't remember saying that, but then again, I've probably forgotten more than I remember about Check Point Smiley Happy

You can look in $FWDIR/state/local/FW1 on the gateway...where you'll find all kinds of stuff.

Danny
Pearl

Re: CLI command to show FW/IPS Policy

Instead of looking for specific commands, you could also install our

Common Check Point Commands (ccc)

script and have them always available by entering: ccc

Re: CLI command to show FW/IPS Policy

fw stat

for policy status.

Kind regards,
Jozko Mrkvicka
Employee
Employee

Re: CLI command to show FW/IPS Policy

the following command will give you TP policy status:

fw stat -b AMW 

0 Kudos