Jump to content
Toggle menu
  • 51 articles
  • 24 files
  • 4 users
  • 750 edits
Tech-Wiki
Toggle preferences menu
Toggle personal menu
Not logged in
Your IP address will be publicly visible if you make any edits.

Inspect and export Check Point gateway connections

From Tech-Wiki


Inspect active Check Point Security Gateway connections and export connection-table information for troubleshooting or offline analysis.

ⓘ
Validation status
Reviewed against the current Check Point R82 CLI Reference Guide on 27 September 2026.
!
Connection tables can be large and sensitive
Detailed connection output can contain internal and external IP addresses, ports, services and policy information. Store exported files appropriately and avoid running unnecessarily expensive table formatting on heavily loaded gateways.

Simplified connection view

Check Point recommends fw ctl conntab when a simplified, formatted view of current connections is sufficient.

>_Show current connections
fw ctl conntab

The command supports filters such as source address, destination address, ports, protocol, service, rule and TCP state.

>_Filter by destination address and port
fw ctl conntab -dip=198.51.100.20 -dport=443

Detailed connections table

For lower-level connection-table details, Check Point recommends fw tab -t connections -f.

>_Show detailed connection-table information
fw tab -t connections -f

Use the detailed table only when the simplified fw ctl conntab view does not provide the required information.

Export for offline analysis

>_Export the simplified connection view
fw ctl conntab > /var/log/fw-connections.txt

For the detailed kernel-table view:

>_Export the detailed connections table
fw tab -t connections -f > /var/log/fw-connections-detailed.txt

Copy the file to an approved analysis location and remove temporary exports when they are no longer required.

Gateway statistics

fw ctl pstat provides internal gateway statistics including connection-related information.

>_Show firewall kernel statistics
fw ctl pstat
✓
Filter before exporting where possible
For a targeted incident, use fw ctl conntab filters to reduce the amount of data collected instead of exporting the entire connection table.

Scalable Platforms and CoreXL

On Scalable Platforms, use the commands in the applicable Security Group as documented by Check Point.

For CoreXL-specific analysis, the fw -i syntax can target an individual Firewall instance when required, but the normal fw commands provide aggregated information in typical troubleshooting.

Official references

See also