CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-01-06
breakdan breakdan is offline
Junior Member
 
Join Date: 2006-12-25
Location: Italy
Posts: 19
Rep Power: 0
breakdan has an average reputation (10+)
Default how to see connectiontable

Hi at all,

firstly i've to thank you for help....i've passed ccsa exam also about you :).
The question: how can i see some detail about connection table built by CP GW without overload the CPU with a CPU-intensive command?

THK and have a good day

Danilo
Reply With Quote
  #2 (permalink)  
Old 2007-01-06
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 875
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: how to see connectiontable

What kind of information are you looking for? It might be available in the "Active" tab of SmartView Tracker without running a manual command.

Ray
Reply With Quote
  #3 (permalink)  
Old 2007-01-06
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 787
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: how to see connectiontable

Quote:
Originally Posted by RayPesek View Post
What kind of information are you looking for? It might be available in the "Active" tab of SmartView Tracker without running a manual command.

Ray

The Active tab places a serious load on the gateway though - there's no way I'd run it on a module with more than a few thousand connections. Usually I just do fw tab -t connections -u to dump the table. Adding the -f flag seems to add a bit more load, so I do my formatting myself.
Reply With Quote
  #4 (permalink)  
Old 2007-01-06
breakdan breakdan is offline
Junior Member
 
Join Date: 2006-12-25
Location: Italy
Posts: 19
Rep Power: 0
breakdan has an average reputation (10+)
Default Re: how to see connectiontable

Quote:
Originally Posted by northlandboy View Post
The Active tab places a serious load on the gateway though - there's no way I'd run it on a module with more than a few thousand connections. Usually I just do fw tab -t connections -u to dump the table. Adding the -f flag seems to add a bit more load, so I do my formatting myself.
Thank you, it was the command that i was looking for....how can you format from yourself the output of command?
And....can i put some filter as in fw monitor...i may see just connection between 2 end point and not all.....
Do you think that command add heavy load on FW (i may have 70.000 - 100.000 connections...).

Cheers
Dani
Reply With Quote
  #5 (permalink)  
Old 2007-01-07
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 787
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: how to see connectiontable

I think the first line tells you what each column is. You can then do your own stuff in perl/awk/whatever to convert hex to dotted decimal. Just standard Unix text processing really.

I don't think you can add a filter to the fw tab command - I think you can only dump the whole thing and grep out what you need.

70-100K is a lot of connections, but it depends on how powerful your firewalls are. Usually I will run the command to dump the table on the secondary firewall in the cluster, since the connections tables are in sync.

As an aside, you can also run this command from the mgmt station - you don't actually need to log onto the firewall. On the mgmt station, run fw tab -t connections -u <fw_name>
Reply With Quote
  #6 (permalink)  
Old 2007-01-07
breakdan breakdan is offline
Junior Member
 
Join Date: 2006-12-25
Location: Italy
Posts: 19
Rep Power: 0
breakdan has an average reputation (10+)
Default Re: how to see connectiontable

Quote:
Originally Posted by northlandboy View Post
I think the first line tells you what each column is. You can then do your own stuff in perl/awk/whatever to convert hex to dotted decimal. Just standard Unix text processing really.

I don't think you can add a filter to the fw tab command - I think you can only dump the whole thing and grep out what you need.

70-100K is a lot of connections, but it depends on how powerful your firewalls are. Usually I will run the command to dump the table on the secondary firewall in the cluster, since the connections tables are in sync.

As an aside, you can also run this command from the mgmt station - you don't actually need to log onto the firewall. On the mgmt station, run fw tab -t connections -u <fw_name>
Thank you for reply...i know 70-100K is lot of conn..ehehhe
i'll try and....i'll say you if the FW get stuck :)

biez

Dani
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 10:31.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0