- Products
- Learn
- Local User Groups
- Partners
- More
Stop Babysitting Rules.
Go Agentic
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Hi,
Do anyone knows if its possible to check the amount of traffic generate from specific servers behind the firewall?
In this case how many Mbit or traffic amount in GB, i guess netflow would do the trick...
Am aware how to check number of connections/logs etc.
But is it possible to get traffic numbers?
Will smartevent catch this or is that limited to webtraffic such as HTTP/HTTPS?
We are running VSX, R80.30 HFA219.
As far as iknow you need to configure generic netflow and not able to have one destination per VS.
So this complicate things within VSX aswell.
Regards
Magnus
Magnus,
I believe it is possible from SmartEvent.
smartevent has a particular generic template with total bandwidth etc.
with some modification to the template, I believe you could achieve this.
I will try create this for you at some point tomorrow if you don’t beat me to it!
hehe thanks!
Smartevent is not my strong side so am sure you will beat me to it 🙂
Only ever used it for websurfing for clients so haven't tried within the network so to say.
Magnus,
Here you go.
The report is abit rough cosmetically, but it will do the job.
Let me know if you want it tidying up.
This will show the top sources on bandwidth usage. To search for the specific source you want, just simply do the usual search in the search bar - "src:xxx.xxx.xxx.xxx"
Note - Make sure accounting is ticked under your log options for your rules!! This is a must! 🙂
Thats quick!, i will try to check it out during the week then.
Still need to install a smartevent box and add to the MDS/MLM 🙂
Accounting on the rules.. That's a pain, 1000rules+ and already logging 50G+ per day.
/Magnus
Accounting is necessary unfortunately. Do you have extended log on any of them rules? Maybe you could look at your logging to try reduce.
Much more and you may need to consider additional correlative units for SmartEvent if you want to use it heavily in production
Now i have installed a smartevent server attached it to the global domain.
added the specific CMA/CLM within Initial settings correlation units and the CMA in object domains
Installed DB, changed all rules to accounting, left it a few hours but well more or less nothing. i get it like 30.000 events system status says OK.
Firewall is generating like 400.000 logs/hour
Will this actually work with FW only? based on your file @JackPrendergast am guessing i do need to activate application controll & url filtering aswell
In this case am looking for bandwidth uses within the check point between interfaces.
Regards,
Magnus
Shouldnt have to enable URLF&APPC - should be fine with FW only with logs set to accounting
Unless I am wrong.. but that should work.
Let me know 🙂
Sadly not get it to work, so currently checking on the possibilitys to do it via netflow.
You should be able to directly attach the .cpr file to a message (or worst case, after zipped).
I tried attaching it directly and it stripped it out. Next time I’ll try zip it! Thanks!
Hello,
I need to know how much traffic (GB or MB) has passed through our firewall in a year for example. Does anyone know how I can get this information?
Thanks
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 23 | |
| 19 | |
| 9 | |
| 9 | |
| 8 | |
| 7 | |
| 7 | |
| 6 | |
| 4 | |
| 4 |
Fri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeThu 04 Jun 2026 @ 07:00 PM (IDT)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - AmericaFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementThu 18 Jun 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point WAF - The Next Generation of AI powered protectionFri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY