Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Timothy_Hall
Champion Champion
Champion
Jump to solution

fw up_execute Equivalent for NAT Rule Matches?

fw up_execute can be run on the gateway to find a matching Network policy rule in the live policy like this:

 

up_execute.png

 

Is there an equivalent CLI utility to find a matching NAT policy rule on the live gateway?  I'm aware that Packet Mode searches can be executed against the NAT policy in the SmartConsole, but I'm looking for a CLI utility on the gateway itself.  Thanks!

    

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin

Haven’t seen and with NAT it’s a bit more complicated due to the fact some of the NAT isn’t handled by actual rules but rather as a result of object definition.

View solution in original post

5 Replies
PhoneBoy
Admin
Admin

Haven’t seen and with NAT it’s a bit more complicated due to the fact some of the NAT isn’t handled by actual rules but rather as a result of object definition.

Timothy_Hall
Champion Champion
Champion

Not even in R81?  It seems like the NAT policy in that version is now acting more like a "real" policy layer, and allowing the use of Security Zones & Dynamic Objects including Access Roles, as well as keeping hit counts.

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
0 Kudos
PhoneBoy
Admin
Admin

Perhaps there's a hidden flag for fw up_execute?

0 Kudos
Richard_Carson
Contributor

bump thread - this would be a useful feature

0 Kudos
Timothy_Hall
Champion Champion
Champion

You can try searching the contents of the fwx_cache table which will hold the most recently hit NAT rules, see my post here:

https://community.checkpoint.com/t5/General-Topics/NAT-Cache-Table-Full/m-p/53547/highlight/true#M10...

 

here is another helpful tool as well:

showtable.sh - it shows statistics of the connecti...

 

 

 

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events