- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- NAT policy rules hit count not visible in .csv exp...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
NAT policy rules hit count not visible in .csv export file
Hey guys,
I was doing some R81.20 lab testing yesterday and its great to see that NAT rules hit count now works consistently, but weird thing is when I export the NAT rules in csv format, I dont see column for hit count.
If I do same for regular rules, its there and I see the actual hit count, like you see it in smart console. I did same for urlf+appc and content awareness ordered layer rules and hit count shows in csv file. I have a feeling maybe this is by design, but not 100% sure. Anyway, not a big deal, just curious : - )
Thanks as always for the help 🙌
Cheers,
Andy
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This issue has been fixed in R81.20 Jumbo 96+, note that not only do you need the latest JHFA installed you must also have the latest version of the SmartConsole as well. Access to the NAT hit counts is now accessible through the management API too:
RJ-51150, |
Security Management |
NEW: In SmartConsole, the CSV export file of Access Policy NAT rules now contains the hit count data: "Hits", "First Hits" and "Last Hits" columns.
|
PRJ-56656, |
Security Management |
NEW: The "show nat-rule" and "show nat-rulebase" Management API commands now support displaying hit count data with optional date range filtering through the "show-hits true" parameter, allowing users to retrieve hit statistics for NAT rules with flexible time-based querying in JSON format. Syntax examples:
|
CET (Europe) Timezone Course Scheduled for July 1-2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@Tomer_Noy does the export for NAT rules via SmartConsole include hit count information?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If not, this is my unofficial RFE sumbission request ; - )
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
We will look into it for the next version and try to backport it to JHF of recent versions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I had customer ask me about it, but I told them since their S1C instance will be upgraded soon to R81.20, at least they will be able to consistently see NAT rules hit count in the dashboard, so thats better than not see it at all : - ). We were hoping with everything being on R81.10 it would work as well, but sadly not...if they are lucky, works one out of 30 policy installs.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Is there any update on this or way to export NAT rules with hit count details. I even tried with mgmt api, looks like the hit count details are not present for NAT rules like in access rules. Please help / share if there is any way.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
We are working to add a NAT hitcount to the Management API and to the export functionality in SmartConsole.
We will deliver it to the Jumbo branch as well once ready.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @Youssef_Obeidal
Do you know if this was already integrated or near integration?
A customer of ours needs this functionality of exporting the NAT rules with hit counts.
Thank you,
Pedro Madeira
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
Thanks for your reply.
I just tested in another customer's R81.20 to export the access control and NAT rule base but I'm still missing hits.
I might be missing some kind of option to include it. The columns I'm getting are:
No.,Type,Name,Original Source,Original Destination,Original Services,Translated Source,Translated Destination,Translated Services,Install On,Comments
Any pointers?
Thank you once again.
PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Did you make sure 100% hits column is enabled?
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes. I have the columns enabled.
Do you think I need a more recent version than JHFA T65?
Which version and JHFA are you using to export?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Im on jumbo 76, but it worked even when I was on way lower jumbo, so thats probably not an issue. Maybe try reboot the mgmt to see if it makes any difference.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I found out what the problem was. I have to have the hits column enabled everywhere for it to be exported, so in Access Control Rules layer, URLF/AppCtrl layer and NAT. If it's not enabled in each one, the export doesn't come out with hits.
I have it working now. Thanks for your tips buddy. You Rock 🙂
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thats right my friend. Glad we can help 🙂
Best,
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Good afternoon! I have the same problem that you had, but in my case I have the HIT column active in all the layers and even so the excel does not export with the hits.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What version of mgmt/gw?
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello good! How's it going? thanks for answering. The MGM 81.20 and GW 81.10
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I cant sadly speak for R81.10, as I never tested it in that version, but in R81.20, both mgmt and gateway, works fine. Let me try in the lab shortly, just to confirm.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@AOBELAR I would open TAC case to check this, since I have R81.20 jumbo 92 in the lab (mgmt and gateways) and hits on NAT rules does NOT show up when you export nat rules (but it does in nat policy), but works on every other layer. I even unchecked hits, push policy, same thing.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
K, this is really bothering me now, lets see if I can solve it till 2025 lol
Btw, I refreshed hit count, installed policy, installed database, no luck...I dont get it. Mind you, since I made this post, I had to reinstall mgmt couple times, but it is latest R81.20 jumbo 92 version, same as gateways.
If I make any headway, will let you know, but will more on it Monday, since its almost end of the day for me. I will try fix in in next 45 mins.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I ended up asking AI copilot and closest thing it found was below, BUT, this does not apply to NAT rules, since option is nott there :- (
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you very much for your answers, the truth is that I try several things, extracting it through API or CLI. I don't understand how to get displays in the Smartconsole yet.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can easily see them in smart console, but when you export nat rules in csv format, you can NOT see hits : - (
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That's how you say, on the SmartConsole I see it perfect.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Let me play around with it more and see. I will reboot mgmt server and try again and let you know.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Nothing...just rebooted, exact same issue, makes no sense.
Its R81.20 latest jumbo, 92.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@PhoneBoy Any clue why this does not seem to work? I even reset all hit_count values in Guidbedit, installed policy, put them back how they were by default, pushed policy again, same issue...all hit counts show for regular layers, but for NAT, absolutely nothing : - (
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I didn't find any logic either.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Lets see what Phoneboy says...I cant honestly think of anything else to try. I even rebooted all the lab gateways as well (on top of mgmt), same problem.
Andy
