Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Vikram_Chhabra
Explorer

Command to know encrypted and clear text communication

is there any command to get the all encrypted and clear text communicating network from SG CLI.?

Actually I need to check how many networks are communicating in encrypted from and how many in clear text.? I have to make an list of both type communication. 

0 Kudos
4 Replies
JozkoMrkvicka
Mentor
Mentor

Option 1:

User SmartLog and see "Top Actions" on the left pane.

Option 2:

cpstat -f statistics vpn

Option 3:

cpview

Kind regards,
Jozko Mrkvicka
0 Kudos
PhoneBoy
Admin
Admin

It depends on how you are defining "encrypted" traffic.

Generally speaking it's better to do this from SmartLog or SmartEvent depending on your criteria and what you're licensed to use.

If you want to see what's active RIGHT NOW on the gateway then you'll have to parse the output of fw tab -t connections -u.

See this SK for details: Connections Table Format 

0 Kudos
Danny
Champion Champion
Champion

I would use this one-liner to get a list of all networks behind all interfaces and check the VPN gateway object for the configured VPN encryption domain to get a list of all networks that are being encrypted.

0 Kudos
JozkoMrkvicka
Mentor
Mentor

In case you have communication from one interface towards another on the same gateway, it is going as clear text, even both networks are in VPN domain.

Another exception is Excluded Services in VPN community.

One more exception are subnets written in crypt.def file.

In all of these scenario, particular subnets are inside VPN domains.

Kind regards,
Jozko Mrkvicka
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events