- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi am new in checkpoint smartconsole and sometime I have to create some policies (source destination and port number) .My question is can we check if the policy is working on smartconsole cli like fortigate diagnose debug .
Thanks for you help.
If you want to check which policy is installed and the time it was installed use one of the following commands on the Security Gateway:
For Access Control Policy
fw stat
cpstat fw
cpstat fw -f <relevant flag>
For Threat Prevention Policy
fw stat -b AMW
The SmartConsole CLI is not going to tell you what policy is currently running on a gateway right now.
And in any case, no policy changes you do in SmartConsole will impact gateways until you explicitly push the policy to them.
Something like the following might be useful to see what the gateway says it’s policy is: https://community.checkpoint.com/t5/General-Topics/Show-Ruleset-and-Objects-on-the-Gateway-Emergency...
If you want to check which policy is installed and the time it was installed use one of the following commands on the Security Gateway:
For Access Control Policy
fw stat
cpstat fw
cpstat fw -f <relevant flag>
For Threat Prevention Policy
fw stat -b AMW
Hi Tal ,
Am new with the checkpoint stuff am more fortigate expert. My new job allow me only to access the smartconsole same as fortimanager (create policy and push to the fortigate)
Am limited access on the physical hardware as you mention (security gateway) my question is can we do a ping option source ip to destination ip on the smartconsole to confirm if the policy is working fine.
Thanks
Note that without any sort of CLI access to the Security Gateway, your troubleshooting capabilities will be very limited.
The SmartConsole CLI only allows you to access the management API.
Seeing as we drop all packets with IP Options enabled by default, you cannot use that to test the policy.
However, I think you'll be able to find the information you're looking for in SmartConsole.
Go to Gateways and Servers and click on the relevant gateway object.
Then find the Device and License information below:
From the resulting window, you should be able to find what policy is installed.
Thanks PhoneBoy,
I will try to get access on the hardware device, so that i can learn the way of troubleshooting level on cli like
Ping
traceroute
details about routing table path .
etc...
hey,
just as an idea, you can run some scripts (CLI) from SmartConsole towards the Cluster or individual member.
by doing that you will not have to SSH to the GW and do other steps.
(right-click on cluster/gw and choose Scripts [top option])
ty,
Thanks
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 22 | |
| 15 | |
| 11 | |
| 7 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY