- Products
- Learn
- Local User Groups
- Partners
-
More
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
IDC Spotlight -
Uplevel The SOC
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Hi all,
In sk85560, it refer to that we can used "fwfonic_bypass [interface name] status" check bypass status.
The Bypass feature works automatically, and normally there is no need for the administrator to manually change the Bypass Card's state. Nevertheless, using the fwfonic_bypass script, administrator can manually activate/deactivate Bypass functionality, and also check the current Bypass status:
Usage:
[Expert@HostName:0]# fwfonic_bypass {<bypass_interface_name> | all} {on | off | status}
Examples:
Note: <bypass_interface_name> is the name for the master interface of the bypass pair.
Status Response Explanation:
Disabled = Fail-open card is not configured to operate in fail open mode.
Off = Fail-open card is configured, but is currently offloading traffic to the firewall for inspection.
On = Fail-open card is configured and is in fail-open mode, passing traffic without inspection.
As the capture screen, I found it appear one bypass interface eth02-01, but eth2-01 and eth2-02 is a pair of bypass interface we used. Is it normal? Thx!
B.R.
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY