- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
From R81 it is possible to delete all sessions matching the filter with the command "fw ctl conntab -x ".
Unfortunately, this does not work for the "rule" filter. Here the complete connection table is deleted 😞
For example:
fw ctl conntab -x -rule=3
Tested with R81.10.
---
fw ctl conntab -h
Usage:
-h/-help # Display this help menu
-x # Delete the selected entries (without this flag, entries are only printed)
-sport # Filter by source port or source port range
-dport # Filter by destination port or detination port range
-proto # Filter by IP protocol or IP protocol range
-sip # Filter by source IP or source IP range
-dip # Filter by destination IP or detination IP range
-rule # Filter by rule or rule range
-service # Filter by service
-type # Filter by type bitmask
-flags # Filter by flags bitmask
-state # Filter by TCP state (SYN_SENT, SYN_ACK, ESTABLISHED, SRC_FIN, DST_FIN, BOTH_FIN)
Using multiple options will display only entries that match both criteria (x AND y)
Usage Examples:
* Display / Delete all port 80 connections in state BOTH_FIN:
fw ctl conntab [-x] -state=BOTH_FIN -dport=80
* Display / Delete all connections from 192.168.X.X:
fw ctl conntab [-x] -sip=192.168.0.0-192.168.255.255
* Display / Delete all old connections:
fw ctl conntab [-x] -flags=0x100/0x100
Any news in this case from Check Point?
Hi,
We are not aware of this issue and are unable to reproduce this in our setup.
Can you please open a ticket with support? this will allow us to get all the required info and do a remote session
Seems to be fixed in R81.20:
fw ctl conntab -x -rule=3
deletes only the rule 3 connections
If you delete the connection in the connection table, it is still contained in the acceleration table and in the Dynamic Dispatcher table. Therefore, you may have some negative effects.
After deletion, they were still contained in the following tabel:
fw ctl multik gconn -p -> Dynamic Dispacher tabel
fwaccel conns -> Acceleration tabel
Personally, I would be very careful about deleting the connetions.
---
Maybe Check Point's R&D can say something about this topic.
Very true - but the rule filter works now...
Hello,
I have a question regarding the following: in the output of the command "fw ctl multik gconn -p", there are some connections that have been present for several days, even though they no longer appear in the current connection table.
No connections were removed manually.
Have you encountered this issue before?
Is there a way to remove these entries from the gconn table without a reboot?
BR,
Zolo
Totally different command, please start a new thread. On a firewall, there are actually three separate tables tracking "connections":
fw ctl multik gconn - Dynamic Dispatcher table on SND cores to ensure the packets of a connection are always "stuck" to the same Firewall Worker Instance. These connections may not necessarily be "alive"; it is just tracking a Firewall Worker Instance core assignment
fwaccel conns - SecureXL's connections table on SND cores for tracking live connections in the fastpath and medium path only
fw tab -t connections & fw ctl conntab - Table for tracking all live connections on the Firewall Worker Instances
Thank you Timothy.
I opened a new thread: Dynamic Dispatcher table - Check Point CheckMates
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
12 | |
12 | |
10 | |
7 | |
6 | |
6 | |
5 | |
5 | |
5 | |
5 |
Tue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY