CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-03-14
miker miker is offline
Junior Member
 
Join Date: 2007-03-09
Posts: 1
Rep Power: 0
miker has an average reputation (10+)
Default Optimizing a rulebase where some rules are set not to log

So, I have a rulebase with several hundred rules, which I would like to optimize, by moving the most-used rules towards the top of the rulebase. I'm quite familiar with methods for taking fw.log and determining what rules have the highest hit counts.

However, this rulebase has many rules set not to log. Naturally, in this case, I cannot use fw.log to determine hit counts on such rules. Is there any way for me to do this?

I suspect 'fw monitor' may have this functionality since it seems to have some awareness of the application level (e.g. you can use 'accept' and 'deny' as expressions), but I can't find any documentation that you can use it to search on rules. Is there an 'fw monitor' expression to do this?

If not with 'fw monitor', is there another method for determining this information? Obviously, I could turn on logging on all the rules, but is there anything besides that?
Reply With Quote
  #2 (permalink)  
Old 2007-03-14
kva.kva kva.kva is offline
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: Optimizing a rulebase where some rules are set not to log

You can install new log module with eval 15 day license. In Global Properties check Reporting Tools -> Enable tracking all rules (including rules marked as None in the Track column) and Send all logs to: New_Log_Module.
Then install Eventia Reporter and try to integrate with log module. Eventia Reporter has report Standard -> Security -> Rule Base Analysis "The report can be used to determine which rules are used the most, which rules are used infrequently and which rules are never used."
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 20:26.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0