- Products
- Learn
- Local User Groups
- Partners
-
More
Celebrate the New Year
With CheckMates!
Value of Security
Vendor Self-Awareness
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
Mobile Security
Buyer's Guide Out Now
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Hi Guys,
I want to find out stale entries in connection table in Checkpoint gateway and want to delete a specific entry from table..
I got some script over internet but that is not certified with Checkpoint so do want to try directly.
Thanks!
Arun Kumar
Hi Arun Kumar,
I recommend you follow the SK103876, but is stressful situation calculating HEX numbers of connections. And then, Kaspars Zibarts wrote a excellent article here about a good method to do it:
How to manually delete an entry from the Connections Table
Regards,
Alisson Lima
There is not out of state entries on the connection table. the security gateway does not storage them, for example if you are under a DDoS attack millions of ACK will arrive to the gateway but non of them will be save on the connection table. for obvious reasons.
You can delete an specific entry with the command bellow however is not recommended on production environments :
# fw tab -t connections -x -e <5 touple on HEX >
Example :
# fw tab -t connections -x -e 0000020,ad1e2f98,0000cb08,ab1aa870,0000470c,00000006
to see your connection table :
#fw tab -t 8158
after the connection is delete you will have some out of state drops until the connection is established once again.
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY