Saturday, March 28, 2009

Checkpoint Firewall - IPSO Standard Health Check

GUI = Smart View Monitor

CLI as below
fw stat
cpstat fw
cphaprob stat

to check the HA state

For Nokia Box, run
clish
show vrrp

Friday, March 27, 2009

Checkpoint Firewall - Fw Monitor

[PDF]
How to use fw monitor
http://www.checkpoint.com/techsupport/downloads/html/ethereal/fw_monitor_rev1_01.pdf

[DOC]
FW MONITOR
www.cpug.org/check_point_resources/FW%20MONITOR_expert.doc

[PDF]
Fw Monitor
www.nokia.com/NOKIA_COM_1/About_Nokia/Press/White_Papers/pdf_files/technicalwhitepaper_fwmonitoring.pdf

grep pix log

cat pix.log | grep "Sep 26 20:" | grep -v Teardown | grep -v Built| grep -v Deny | grep -v Accessed| grep -v access-list | grep -v Inbound | grep -v Deny | grep -v Accessed| grep -v access-list | grep "PIX-1-"

Thursday, March 26, 2009

Cisco Pix Firewall - Standard Health Check

1.
sh fail
- untuk cek yg mana primary atau secondary yg tengah active atau standby
- bila tarikh last failover
- cek status sume fw interface

2.
sh conn count
- cek bape byk bilangan connection, kalau banyak betulla tu fw tengah pass traffic

3.
sh conn
- nak tengok connection

4.
sh mem
- cek fw memory

5.
sh cpu usage
- cek fw cpu utilization

6.
sh int
- cek sume interface kat fw

LinkWithin

Related Posts with Thumbnails