- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: How to see what firewall rules match some traf...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to see what firewall rules match some traffic
I need to see what firewall rules match some traffic. There are a lot of rules in my policy, accordingly, not all rules are logged. What kind of debug and which flags can I use for this purpose (except the flag "conn")? Or what method can I use for this purpose?
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Not exactly what you want, but sort of
https://community.checkpoint.com/thread/5319-my-top-3-check-point-cli-commands#comment-14596
EDIT: Check this thread:
CPT - Check Point Packet Trace Utility ?
EDIT2:
And the winner is (hidden tool in R80):
Jozko Mrkvicka
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Maybe this helps: sk85780 - How to use the 'connstat' utility
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Unfortunately, no. Connstat we can use only for Windows. For Gaia we can use CPmonitor, but is not supported on a 64-bit based OS.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I do not understand - you can collect the table using
fw tab -t connections -u > /var/log/Connections_Table.txt
transfer it to the PC and run the utility with the relevant flags:
C:\> connStat.exe -f Name_of_Table_File.txt [-a|-c|-s|-r|-l|-p|-d|-n <number>] > Name_of_Output_File.txt
Also, CPMonitor 32bit limitation should not apply here.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for explanation, but it does not suit me, unfortunately.
I need to see what rule number match traffic with specific dst and src address.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Now i understand! This is all in the used connections table, but you must analyze it yourself, see sk65133: Connections Table Format
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Not exactly what you want, but sort of
https://community.checkpoint.com/thread/5319-my-top-3-check-point-cli-commands#comment-14596
EDIT: Check this thread:
CPT - Check Point Packet Trace Utility ?
EDIT2:
And the winner is (hidden tool in R80):
Jozko Mrkvicka
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
fw up_execute is a winner, you are right)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello
The easy Way enable on Smart Console the Option Hit than you can see if the all the Policys are in use.
Alexander
