Firewall-1

Re: [FW-1] lesser of two evils. Which is the preferred method?

Subject: Re: [FW-1] lesser of two evils. Which is the preferred method?
From: sin <sin AT IMACANDI DOT NET>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Date: Tue, 6 Mar 2007 18:39:52 +0200
cisco4ng wrote:
> Hi All,
> 
> In the past on CP 4.1, NG and NG AI, when finding out the number of active
> connections on the Nokia firewall, I performed the following command:
> 
> fw tab -s -t connections
> 
> The problem is that when the firewall is under extreme high cpu usage, 
> sometimes
> it can cause the firewall to stop traffics,  especially  with NG Feature Pack 
> 3 
> 
> I also learned that starting with Checkpoint NG Feature Pack 3, there is 
> another
> command that will also do just that.  The command is:
> 
> cpstat fw -f policy
> 
> It will show me the same thing as the previous command.  I found out that
> this command works better even when the firewall is under extreme high
> cpu usage but I've not tried it extensively to know what the downside might 
> be.
> 
> Any comments?  Thanks.

why don't you just try and see which one works best for you ?

I mean it's less time consuming than asking the list what commands you
should run on your firewalls.

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================

<Prev in Thread] Current Thread [Next in Thread>