CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Eventia Analyzer/Reporter/SmartView Reporter
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-03-19
MBreve MBreve is offline
Junior Member
 
Join Date: 2006-01-19
Location: Amsterdam
Posts: 11
Rep Power: 0
MBreve has an average reputation (10+)
Default Traffic by rulebase

Hi,

I'm looking for a way to report traffic volumes by rulebase number.

The standard reports don't offer this and I can't find a way to report this.

For all the rules I want to monitor I've set the log option to Account.

Am I missing something or is this simple option not possible?

TIA,

Marc
Reply With Quote
  #2 (permalink)  
Old 2007-03-19
melipla melipla is offline
Senior Member
 
Join Date: 2006-01-25
Posts: 724
Rep Power: 3
melipla has an average reputation (10+)
Default Re: Traffic by rulebase

I believe you have to use Eventia Reporter to interpret the Accouting information.

HTH
Reply With Quote
  #3 (permalink)  
Old 2007-03-20
MBreve MBreve is offline
Junior Member
 
Join Date: 2006-01-19
Location: Amsterdam
Posts: 11
Rep Power: 0
MBreve has an average reputation (10+)
Default Re: Traffic by rulebase

I am using Eventia Reporter.

But all I have are the pre-defined standard reports. None of these will report traffic volumes per rulebase number.

The options to configure your own report are so limited it's hardly useable.

I can't imagine that a simple request like this sin't possible with Eventia Reporter (which we especially purchased for this report).
Reply With Quote
  #4 (permalink)  
Old 2007-03-20
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,603
Rep Power: 4
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Traffic by rulebase

If you already own EVR and have it on support, I would strongly recommend that you upgrade to EVR R63. There have been several reports added and configuring the reports is easer than in older versions.

I don't know that what you are looking for is in there, but if its not open a ticket/RFE on it. The process of adding reports to EVR has been improved as well (Dynamic download instead of upgrades).
Reply With Quote
  #5 (permalink)  
Old 2007-03-20
MBreve MBreve is offline
Junior Member
 
Join Date: 2006-01-19
Location: Amsterdam
Posts: 11
Rep Power: 0
MBreve has an average reputation (10+)
Default Re: Traffic by rulebase

Thanks!

We do have full support.

The current version is R61, any idea if I can install Eventia R63 right away or do I need to upgrade to R62 first for the SmartCenter.

Bye,

Marc
Reply With Quote
  #6 (permalink)  
Old 2007-03-20
kva.kva kva.kva is offline
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: Traffic by rulebase

Eventia Reporter R63 can be upgraded from version R56 and up.
But don't forget read the upgrade guide, because R63 has a new architecture. And Upgrade process is not so simple.
Reply With Quote
  #7 (permalink)  
Old 2007-03-20
MBreve MBreve is offline
Junior Member
 
Join Date: 2006-01-19
Location: Amsterdam
Posts: 11
Rep Power: 0
MBreve has an average reputation (10+)
Default Re: Traffic by rulebase

Thanks for the info.

I've downloaded the whitepapers and I don't expect a problem.

I wanted to download the software as well but they charge $25 for the CD and shipping. I'll wait to see if Eventia R63 is included in the R65 package I ordered last week. I hope they include Eventie R63 as well.
Reply With Quote
  #8 (permalink)  
Old 2007-03-21
melipla melipla is offline
Senior Member
 
Join Date: 2006-01-25
Posts: 724
Rep Power: 3
melipla has an average reputation (10+)
Default Re: Traffic by rulebase

Quote:
Originally Posted by MBreve View Post
I wanted to download the software as well but they charge $25 for the CD and shipping. I'll wait to see if Eventia R63 is included in the R65 package I ordered last week. I hope they include Eventie R63 as well.
Ah my biggest complaint :) If you have a support contract you can get it for free, you just have to go about it a funny way. Go to this URL:
https://supportcenter.checkpoint.com...MainSearch.jsp
After you login, under "Download Software" there's a link to "Upgrade Kits". You can order through here for free (once per product I believe).
Reply With Quote
  #9 (permalink)  
Old 2007-03-22
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,603
Rep Power: 4
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Traffic by rulebase

Quote:
Originally Posted by MBreve View Post
Thanks for the info.

I've downloaded the whitepapers and I don't expect a problem.

I wanted to download the software as well but they charge $25 for the CD and shipping. I'll wait to see if Eventia R63 is included in the R65 package I ordered last week. I hope they include Eventie R63 as well.
Eventia R65 is included on the R65 CDs. It's the same thing with newer SPLAT drivers.

BTW they did post the ISO's for R65 on the download center. It's not been the fastest thing in thew world, but I suspect that has to do with the number of people d/l'ing it.
Reply With Quote
  #10 (permalink)  
Old 2007-03-22
MBreve MBreve is offline
Junior Member
 
Join Date: 2006-01-19
Location: Amsterdam
Posts: 11
Rep Power: 0
MBreve has an average reputation (10+)
Default Re: Traffic by rulebase

I did have quite a few problems reaching several CheckPoint servers the last two days.

I hoped to find the R65 ISO's but all I found was a link to order the CD's. I planned to order them anyway but I hoped to get started last sunday.
Reply With Quote
  #11 (permalink)  
Old 2007-03-23
melipla melipla is offline
Senior Member
 
Join Date: 2006-01-25
Posts: 724
Rep Power: 3
melipla has an average reputation (10+)
Default Re: Traffic by rulebase

Quote:
Originally Posted by chillyjim View Post
BTW they did post the ISO's for R65 on the download center. It's not been the fastest thing in thew world, but I suspect that has to do with the number of people d/l'ing it.
Nice! And I was waiting for the CD's too. 10 minutes to download isn't bad.
Reply With Quote
  #12 (permalink)  
Old 2007-03-24
MBreve MBreve is offline
Junior Member
 
Join Date: 2006-01-19
Location: Amsterdam
Posts: 11
Rep Power: 0
MBreve has an average reputation (10+)
Default Re: Traffic by rulebase

10 minutes?

Mine will take double that.

Anyway, I'm happy they're online so I can try some things out.

Funny to see they weren't online last sunday...
Reply With Quote
  #13 (permalink)  
Old 2007-03-29
Reaper Reaper is offline
Member
 
Join Date: 2006-11-15
Location: Tallinn, Estonia
Posts: 82
Rep Power: 2
Reaper has an average reputation (10+)
Send a message via Skype™ to Reaper
Default Re: Traffic by rulebase

I wonder where can i download it?
__________________
CCNA certified
Reply With Quote
  #14 (permalink)  
Old 2007-04-07
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,603
Rep Power: 4
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Traffic by rulebase

http://downloads.checkpoint.com/dc/s...&os=&x=14&y=14
Reply With Quote
  #15 (permalink)  
Old 2007-04-09
Reaper Reaper is offline
Member
 
Join Date: 2006-11-15
Location: Tallinn, Estonia
Posts: 82
Rep Power: 2
Reaper has an average reputation (10+)
Send a message via Skype™ to Reaper
Default Re: Traffic by rulebase

Thanks, got it. Now i just have to wait for IPSO version.
__________________
CCNA certified
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 22:20.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0