Inspect and export Check Point gateway connections
More actions
Inspect active Check Point Security Gateway connections and export connection-table information for troubleshooting or offline analysis.
Simplified connection view
Check Point recommends fw ctl conntab when a simplified, formatted view of current connections is sufficient.
fw ctl conntab
The command supports filters such as source address, destination address, ports, protocol, service, rule and TCP state.
fw ctl conntab -dip=198.51.100.20 -dport=443
Detailed connections table
For lower-level connection-table details, Check Point recommends fw tab -t connections -f.
fw tab -t connections -f
Use the detailed table only when the simplified fw ctl conntab view does not provide the required information.
Export for offline analysis
fw ctl conntab > /var/log/fw-connections.txt
For the detailed kernel-table view:
fw tab -t connections -f > /var/log/fw-connections-detailed.txt
Copy the file to an approved analysis location and remove temporary exports when they are no longer required.
Gateway statistics
fw ctl pstat provides internal gateway statistics including connection-related information.
fw ctl pstat
fw ctl conntab filters to reduce the amount of data collected instead of exporting the entire connection table.Scalable Platforms and CoreXL
On Scalable Platforms, use the commands in the applicable Security Group as documented by Check Point.
For CoreXL-specific analysis, the fw -i syntax can target an individual Firewall instance when required, but the normal fw commands provide aggregated information in typical troubleshooting.