- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hey guys,
Apologies if this was answered before, but I remember while back, I always used to run command that would show me top 10 used rules on the firewall, but cant recall now what it was, as its been probably close to 10 years since I ran it. I know connstat, but thats only for windows. I also tried cpstat blades, but it does not show me anything there.
I think it was some sort of flag with fw tab, but IM not sure. If someone has an idea, would appreciate any feedback.
Tx as always!
Had a look at below, but not exactly what Im after:
sk85780: How to use the 'connstat' utility
Thanks G, but thats only for Windows, this command was done from the fw itself.
Andy
cpstat blades# cpstat blades
Packets accepted : 766249577
Packets dropped : 24321576
Peak number of connections: 19013
Number of connections: 5797
Top Rule Hits
-----------------------
|rule index|rule count|
-----------------------
|Rule 24 | 170186|
|Rule 36 | 59828|
|Rule 2 | 27792|
|Rule 15 | 1234|
|Rule 18 | 1026|
-----------------------Weird...run it on vmware and actual 6000 series appliance, nothing.
I have run the command in a Standalone environment, which is on an OPEN SERVER, and I get no results either.
It is very strange. 😣
Hello,
This command must be applied on the GW?
Or is it on the SMS?
Greetings.
Gateway, of course.
On managements you can use this command:psql_client monitoring postgres -c "select hits,rule_uid,netobj_name,policy_type from hitcount order by hits DESC"
Its cloud instance, so no ssh access.
So your Management is Smart-1 Cloud and your gateways are on-prem?
Correct, for the customer, but in my lab, its all on prem.
Btw, that command shows me top 5 rules for one customer using 6200, but another using 6400, nothing...wonder why. Also, my lab fw, in esxi, shows nothing for top rules.
Was hit count enabled on all these ?
Yes sir Gunther...as a matter of fact, enabled for the last 2 years, which is maximum.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 26 | |
| 17 | |
| 13 | |
| 12 | |
| 7 | |
| 6 | |
| 6 | |
| 5 | |
| 4 | |
| 4 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY