Analyzing the Rule Base Hit Count

Use the Hit Count feature to show the number of connections that each ruleClosed Set of traffic parameters and other conditions in a Rule Base (Security Policy) that cause specified actions to be taken for a communication session. matches.

Use the Hit Count data to:

  • Analyze a Rule BaseClosed All rules configured in a given Security Policy. Synonym: Rulebase. - You can delete rules that have no matching connection

    Note - If you see a rule with a zero Hit Count it only means that in the Security Gateways enabled with Hit Count there were no matching connections. There can be matching connections on other Security Gateways.

  • Better understand the behavior of the Access Control Policy

The Hit Count value appears as:

  • The percentage of the rule hits from total hits

  • The indicator level (very high, high, medium, low, or zero)

The percentage and indicator level are configured in the Access Control Policy Rule Base.

When you enable Hit Count, the Security Management ServerClosed Dedicated Check Point server that runs Check Point software to manage the objects and policies in a Check Point environment within a single management Domain. Synonym: Single-Domain Security Management Server. collects the data from supported Security Gateways (version R75.40 and higher).

Hit Count works independently from logging and tracks the hits even if the Track option is None.

Note - From R81, Hit Count is also supported in the NAT Rule Base (requires Security Gateways R81 and higher).

Enabling or Disabling Hit Count

By default, Hit Count is globally enabled for all supported Security Gateways. The timeframe setting that defines the data collection time range is configured globally. If necessary, you can disable Hit Count for one or more Security Gateways.

After you enable or disable Hit Count you must install the Policy for the Security GatewayClosed Dedicated Check Point server that runs Check Point software to inspect traffic and enforce Security Policies for connected network resources. to start or stop collecting data.

Hit Count Display