Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
the_rock
Legend
Legend

Getting top used rules via command line

Hey guys,

Apologies if this was answered before, but I remember while back, I always used to run command that would show me top 10 used rules on the firewall, but cant recall now what it was, as its been probably close to 10 years since I ran it. I know connstat, but thats only for windows. I also tried cpstat blades, but it does not show me anything there.

I think it was some sort of flag with fw tab, but IM not sure. If someone has an idea, would appreciate any feedback.

Tx as always!

 

Had a look at below, but not exactly what Im after:

https://community.checkpoint.com/t5/General-Topics/How-to-see-what-firewall-rules-match-some-traffic...

https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_NextGenSecurityGateway_Guide/Topic...

 

0 Kudos
13 Replies
G_W_Albrecht
Legend
Legend

sk85780: How to use the 'connstat' utility

CCSE CCTE CCSM SMB Specialist
0 Kudos
the_rock
Legend
Legend

Thanks G, but thats only for Windows, this command was done from the fw itself.

Andy

0 Kudos
Danny
Champion Champion
Champion

cpstat blades
# cpstat blades

Packets accepted :          766249577
Packets dropped :           24321576
Peak number of connections: 19013
Number of connections:      5797

Top Rule Hits
-----------------------
|rule index|rule count|
-----------------------
|Rule 24   |    170186|
|Rule 36   |     59828|
|Rule 2    |     27792|
|Rule 15   |      1234|
|Rule 18   |      1026|
-----------------------
0 Kudos
the_rock
Legend
Legend

Weird...run it on vmware and actual 6000 series appliance, nothing.

0 Kudos
Matlu
Advisor

I have run the command in a Standalone environment, which is on an OPEN SERVER, and I get no results either.

It is very strange. 😣

0 Kudos
Matlu
Advisor

Hello,

This command must be applied on the GW?
Or is it on the SMS?

Greetings.

0 Kudos
Danny
Champion Champion
Champion

Gateway, of course.
On managements you can use this command:
psql_client monitoring postgres -c "select hits,rule_uid,netobj_name,policy_type from hitcount order by hits DESC"

0 Kudos
the_rock
Legend
Legend

Its cloud instance, so no ssh access.

0 Kudos
Danny
Champion Champion
Champion

So your Management is Smart-1 Cloud and your gateways are on-prem?

0 Kudos
the_rock
Legend
Legend

Correct, for the customer, but in my lab, its all on prem.

0 Kudos
the_rock
Legend
Legend

Btw, that command shows me top 5 rules for one customer using 6200, but another using 6400, nothing...wonder why. Also, my lab fw, in esxi, shows nothing for top rules.

 

0 Kudos
G_W_Albrecht
Legend
Legend

Was hit count enabled on all these ?

CCSE CCTE CCSM SMB Specialist
0 Kudos
the_rock
Legend
Legend

Yes sir Gunther...as a matter of fact, enabled for the last 2 years, which is maximum.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events