- Products
- Learn
- Local User Groups
- Partners
-
More
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
IDC Spotlight -
Uplevel The SOC
Important! R80 and R80.10
End Of Support around the corner (May 2021)
So i came across this command somewhere on checkmates-
[Expert@VWC-FW08:0]# fw tab -u -t connections | grep -i 10.8.196.217 | grep -i 40.97.136.200
[Expert@VWC-FW08:0]# fw tab -u -t connections | grep -i 0A08C4D9 | grep -i 286188C8
Where in place of the ips you are suppose to put the hex value which i did as you can see on the second command but why doesn't it display any output for that particular connection?? Its just a random src ip and dst ip that i took out from the logs for this particular gateway just before typing the command, so shouldnt it work, like it displays nothing unless my syntax is wrong but then again upong executing the command i see no error? By the way gateway is in cluster and is a 5900 series running R80.20.
Thanks and regards.
Actually I just wanted to check out this command, that's all, not troubleshooting anything, and the connection was still alive since when I just typed the source IP it was showing the output, when I typed both the source and destination then it didn't show anything, is there a specific syntax for both source and destination?
You probably need to take NAT into account.
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY