- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: fw sam syntax
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
fw sam syntax
Hello mates!
We're testing smart event policy and faced next question. If we understood right, if host was blocked because of policy, it block with SAM (logs shows sam rules numbers). Now we're trying to find ways to unblock host before its timeout ends. If we're trying to use fw sam with flag -C and criteria src, we recieves output as from -help flag, and host still blocked. But, if we're using -D flag, all works properly.
For example
fw sam -v -s localhost -f GWIP -C src 1.1.1.1 - facing -help output
fw sam -D - everything correct, hosts unblocked.
Are we missing anything in first example? Tested both on 81.10 and 81.20 with last JHF takes
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_CLI_ReferenceGuide/Topics-CL... we read:
|
Cancels the
|
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
So, we need not only source, but also destination and all other params to unblock?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have a gut feeling its failing due to localhost. Let me see if I can test it in the lab.
Andy
